From b58843ca9f7770f9539796a4e7a1bcd5d42e593c Mon Sep 17 00:00:00 2001 From: divious1 Date: Wed, 10 Feb 2021 22:35:58 -0500 Subject: [PATCH] added datamodels as an array --- .../email_files_written_outside_of_the_outlook_directory.yml | 3 ++- ...le_okta_users_with_invalid_credentails_from_the_same_ip.yml | 2 +- detections/application/okta_account_lockout_events.yml | 2 +- detections/application/okta_failed_sso_attempts.yml | 2 +- .../application/okta_user_logins_from_multiple_cities.yml | 2 +- .../application/web_servers_executing_suspicious_processes.yml | 3 ++- detections/cloud/abnormally_high_cloud_instances_destroyed.yml | 3 ++- detections/cloud/abnormally_high_cloud_instances_launched.yml | 3 ++- ...bnormally_high_number_of_cloud_infrastructure_api_calls.yml | 3 ++- ...bnormally_high_number_of_cloud_security_group_api_calls.yml | 3 ++- ...s_cross_account_activity_from_previously_unseen_account.yml | 3 ++- ...ect_users_creating_keys_with_encrypt_policy_without_mfa.yml | 2 +- ...aws_detect_users_with_kms_keys_performing_encryption_s3.yml | 2 +- ...network_access_control_list_created_with_all_open_ports.yml | 2 +- detections/cloud/aws_network_access_control_list_deleted.yml | 2 +- .../cloud_api_calls_from_previously_unseen_user_roles.yml | 3 ++- ...loud_compute_instance_created_by_previously_unseen_user.yml | 3 ++- ...ud_compute_instance_created_in_previously_unused_region.yml | 3 ++- ...d_compute_instance_created_with_previously_unseen_image.yml | 3 ++- ...e_instance_created_with_previously_unseen_instance_type.yml | 3 ++- .../cloud_instance_modified_with_previously_unseen_user.yml | 3 ++- .../cloud/cloud_provisioning_from_previously_unseen_city.yml | 3 ++- .../cloud_provisioning_from_previously_unseen_country.yml | 3 ++- .../cloud_provisioning_from_previously_unseen_ip_address.yml | 3 ++- .../cloud/cloud_provisioning_from_previously_unseen_region.yml | 3 ++- detections/cloud/detect_aws_console_login_by_new_user.yml | 3 ++- .../cloud/detect_aws_console_login_by_user_from_new_city.yml | 3 ++- .../detect_aws_console_login_by_user_from_new_country.yml | 3 ++- .../cloud/detect_aws_console_login_by_user_from_new_region.yml | 3 ++- detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml | 2 +- detections/cloud/detect_new_open_gcp_storage_buckets.yml | 2 +- detections/cloud/detect_new_open_s3_buckets.yml | 2 +- detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml | 2 +- detections/cloud/detect_s3_access_from_a_new_ip.yml | 2 +- ...etect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml | 2 +- .../cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml | 2 +- .../detect_spike_in_blocked_outbound_traffic_from_your_aws.yml | 2 +- detections/cloud/detect_spike_in_s3_bucket_deletion.yml | 2 +- .../high_number_of_login_failures_from_a_single_source.yml | 2 +- detections/cloud/new_container_uploaded_to_aws_ecr.yml | 2 +- detections/cloud/o365_bypass_mfa_via_trusted_ip.yml | 2 +- detections/cloud/o365_disable_mfa.yml | 2 +- .../cloud/o365_excessive_authentication_failures_alert.yml | 2 +- detections/cloud/o365_pst_export_alert.yml | 2 +- detections/cloud/o365_suspicious_admin_email_forwarding.yml | 2 +- detections/cloud/o365_suspicious_rights_delegation.yml | 2 +- detections/cloud/o365_suspicious_user_email_forwarding.yml | 2 +- .../abnormally_high_aws_instances_launched_by_user.yml | 2 +- .../abnormally_high_aws_instances_launched_by_user___mltk.yml | 2 +- .../abnormally_high_aws_instances_terminated_by_user.yml | 2 +- ...abnormally_high_aws_instances_terminated_by_user___mltk.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_city.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_country.yml | 2 +- ...ws_cloud_provisioning_from_previously_unseen_ip_address.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_region.yml | 2 +- .../deprecated/clients_connecting_to_multiple_dns_servers.yml | 3 ++- .../deprecated/cloud_network_access_control_list_deleted.yml | 2 +- .../deprecated/detect_api_activity_from_users_without_mfa.yml | 2 +- .../detect_aws_api_activities_from_unapproved_accounts.yml | 2 +- ...ect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 3 ++- detections/deprecated/detect_long_dns_txt_record_response.yml | 3 ++- detections/deprecated/detect_mimikatz_using_loaded_images.yml | 2 +- .../detect_mimikatz_via_powershell_and_eventcode_4703.yml | 2 +- detections/deprecated/detect_new_api_calls_from_user_roles.yml | 2 +- detections/deprecated/detect_new_user_aws_console_login.yml | 2 +- detections/deprecated/detect_spike_in_aws_api_activity.yml | 2 +- detections/deprecated/detect_spike_in_network_acl_activity.yml | 2 +- .../deprecated/detect_spike_in_security_group_activity.yml | 2 +- detections/deprecated/detect_usb_device_insertion.yml | 3 ++- .../detect_web_traffic_to_dynamic_domain_providers.yml | 3 ++- detections/deprecated/detection_of_dns_tunnels.yml | 3 ++- ...dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 3 ++- .../ec2_instance_modified_with_previously_unseen_user.yml | 2 +- .../ec2_instance_started_in_previously_unseen_region.yml | 2 +- .../ec2_instance_started_with_previously_unseen_ami.yml | 2 +- ...2_instance_started_with_previously_unseen_instance_type.yml | 2 +- .../ec2_instance_started_with_previously_unseen_user.yml | 2 +- .../execution_of_file_with_spaces_before_extension.yml | 3 ++- .../extended_period_without_successful_netbackup_backups.yml | 2 +- .../deprecated/first_time_seen_command_line_argument.yml | 3 ++- detections/deprecated/gcp_gcr_container_uploaded.yml | 2 +- detections/deprecated/identify_new_user_accounts.yml | 2 +- ...ll_process___multiple_suspicious_command_line_arguments.yml | 3 ++- detections/deprecated/monitor_dns_for_brand_abuse.yml | 3 ++- detections/deprecated/open_redirect_in_splunk_web.yml | 2 +- detections/deprecated/osquery_pack___coldroot_detection.yml | 2 +- detections/deprecated/processes_created_by_netsh.yml | 3 ++- detections/deprecated/prohibited_software_on_endpoint.yml | 3 ++- ...eg_exe_used_to_hide_files_directories_via_registry_keys.yml | 3 ++- detections/deprecated/remote_registry_key_modifications.yml | 2 +- detections/deprecated/remote_wmi_command_attempt.yml | 3 ++- .../scheduled_tasks_used_in_badrabbit_ransomware.yml | 3 ++- .../deprecated/splunk_enterprise_information_disclosure.yml | 2 +- .../deprecated/suspicious_changes_to_file_associations.yml | 2 +- detections/deprecated/suspicious_file_write.yml | 2 +- .../suspicious_writes_to_system_volume_information.yml | 2 +- detections/deprecated/uncommon_processes_on_endpoint.yml | 3 ++- detections/deprecated/unsigned_image_loaded_by_lsass.yml | 2 +- detections/deprecated/unsuccessful_netbackup_backups.yml | 2 +- detections/deprecated/windows_connhost_exe_force_flag.yml | 2 +- detections/deprecated/windows_disableantispyware_reg.yml | 3 ++- detections/deprecated/windows_hosts_file_modification.yml | 2 +- detections/endpoint/access_lsass_memory_for_dump_creation.yml | 2 +- .../endpoint/attempt_to_add_certificate_to_untrusted_store.yml | 3 ++- ...t_powershell_execution_policy_to_unrestricted_or_bypass.yml | 3 ++- detections/endpoint/attempt_to_stop_security_service.yml | 3 ++- .../attempted_credential_dump_from_registry_via_reg_exe.yml | 3 ++- detections/endpoint/batch_file_write_to_system32.yml | 3 ++- detections/endpoint/bcdedit_failure_recovery_modification.yml | 3 ++- detections/endpoint/common_ransomware_extensions.yml | 3 ++- detections/endpoint/common_ransomware_notes.yml | 3 ++- .../endpoint/create_local_admin_accounts_using_net_exe.yml | 3 ++- .../endpoint/create_or_delete_windows_shares_using_net_exe.yml | 3 ++- detections/endpoint/create_remote_thread_into_lsass.yml | 2 +- detections/endpoint/creation_of_shadow_copy.yml | 3 ++- .../creation_of_shadow_copy_with_wmic_and_powershell.yml | 3 ++- .../credential_dumping_via_copy_command_from_shadow_copy.yml | 3 ++- .../endpoint/credential_dumping_via_symlink_to_shadow_copy.yml | 3 ++- detections/endpoint/deleting_shadow_copies.yml | 3 ++- .../detect_activity_related_to_pass_the_hash_attacks.yml | 2 +- .../detect_computer_changed_with_anonymous_account.yml | 2 +- .../detect_credential_dumping_through_lsass_access.yml | 2 +- .../detect_excessive_account_lockouts_from_endpoint.yml | 3 ++- detections/endpoint/detect_excessive_user_account_lockouts.yml | 3 ++- detections/endpoint/detect_mshta_inline_hta_execution.yml | 3 ++- detections/endpoint/detect_mshta_renamed.yml | 2 +- detections/endpoint/detect_mshta_url_in_command_line.yml | 3 ++- detections/endpoint/detect_new_local_admin_account.yml | 2 +- .../detect_path_interception_by_creation_of_program_exe.yml | 3 ++- ...ocesses_used_for_system_network_configuration_discovery.yml | 3 ++- .../detect_prohibited_applications_spawning_cmd_exe.yml | 3 ++- detections/endpoint/detect_psexec_with_accepteula_flag.yml | 3 ++- detections/endpoint/detect_rare_executables.yml | 3 ++- detections/endpoint/detect_rundll32_inline_hta_execution.yml | 3 ++- .../detect_use_of_cmd_exe_to_launch_script_interpreters.yml | 3 ++- detections/endpoint/disabling_remote_user_account_control.yml | 2 +- detections/endpoint/dump_lsass_via_comsvcs_dll.yml | 3 ++- .../endpoint/execution_of_file_with_multiple_extensions.yml | 3 ++- detections/endpoint/file_with_samsam_extension.yml | 3 ++- detections/endpoint/first_time_seen_child_process_of_zoom.yml | 3 ++- .../endpoint/hiding_files_and_directories_with_attrib_exe.yml | 3 ++- .../endpoint/kerberoasting_spn_request_with_rc4_encryption.yml | 2 +- ...rshell_process___connect_to_internet_with_hidden_window.yml | 3 ++- .../malicious_powershell_process___encoded_command.yml | 3 ++- .../malicious_powershell_process___execution_policy_bypass.yml | 3 ++- ...alicious_powershell_process_with_obfuscation_techniques.yml | 3 ++- .../endpoint/monitor_registry_keys_for_print_monitors.yml | 2 +- detections/endpoint/nltest_domain_trust_discovery.yml | 3 ++- detections/endpoint/overwriting_accessibility_binaries.yml | 3 ++- .../process_creating_lnk_file_in_suspicious_location.yml | 2 +- detections/endpoint/process_execution_via_wmi.yml | 2 +- detections/endpoint/processes_launching_netsh.yml | 3 ++- .../reg_exe_manipulating_windows_services_registry_keys.yml | 3 ++- .../endpoint/registry_keys_for_creating_shim_databases.yml | 2 +- detections/endpoint/registry_keys_used_for_persistence.yml | 2 +- .../endpoint/registry_keys_used_for_privilege_escalation.yml | 2 +- detections/endpoint/remote_process_instantiation_via_wmi.yml | 3 ++- detections/endpoint/rundll_loading_dll_by_ordinal.yml | 3 ++- detections/endpoint/ryuk_test_files_detected.yml | 2 +- detections/endpoint/samsam_test_file_write.yml | 3 ++- detections/endpoint/sc_exe_manipulating_windows_services.yml | 3 ++- .../endpoint/scheduled_task_deleted_or_created_via_cmd.yml | 3 ++- .../endpoint/schtasks_scheduling_job_on_remote_system.yml | 3 ++- detections/endpoint/schtasks_used_for_forcing_a_reboot.yml | 3 ++- detections/endpoint/script_execution_via_wmi.yml | 2 +- detections/endpoint/shim_database_file_creation.yml | 2 +- .../shim_database_installation_with_suspicious_parameters.yml | 3 ++- detections/endpoint/short_lived_windows_accounts.yml | 3 ++- detections/endpoint/single_letter_process_on_endpoint.yml | 3 ++- .../ssa___applying_stolen_credentials_via_mimikatz_modules.yml | 2 +- ...a___applying_stolen_credentials_via_powersploit_modules.yml | 2 +- ...sa___assess_credential_strength_via_dsinternals_modules.yml | 2 +- ...a___attempted_credential_dump_from_registry_via_reg_exe.yml | 2 +- ...___credential_extraction_dsinternals_conversion_modules.yml | 2 +- .../ssa___credential_extraction_dsinternals_modules.yml | 2 +- .../ssa___credential_extraction_fgdump_cachedump_s_option.yml | 2 +- .../ssa___credential_extraction_fgdump_cachedump_v_option.yml | 2 +- .../ssa___credential_extraction_getaddbaccount_from_dump.yml | 2 +- .../ssa___credential_extraction_lazagne_command_options.yml | 2 +- .../endpoint/ssa___credential_extraction_mimikatz_modules.yml | 2 +- .../ssa___credential_extraction_ms_debuggers_kernel_peek.yml | 2 +- .../ssa___credential_extraction_ms_debuggers_z_option.yml | 2 +- .../ssa___credential_extraction_powersploit_modules.yml | 2 +- .../endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml | 2 +- detections/endpoint/ssa___detect_kerberoasting.yml | 2 +- detections/endpoint/ssa___detect_pass_hash.yml | 2 +- detections/endpoint/ssa___first_time_seen_cmd_line.yml | 2 +- ...a___illegal_access_user_content_via_powersploit_modules.yml | 2 +- .../ssa___illegal_account_creation_via_powersploit_modules.yml | 2 +- ..._illegal_account_enable_disable_via_dsinternals_modules.yml | 2 +- .../ssa___illegal_log_deletion_via_mimikatz_modules.yml | 2 +- ...gement_AD_elements_and_policies_via_dsinternals_modules.yml | 2 +- ...ement_computers_and_AD_elements_via_powersploit_modules.yml | 2 +- ...ilege_elevation_and_persistence_via_powersploit_modules.yml | 2 +- .../ssa___illegal_privilege_elevation_via_mimikatz_modules.yml | 2 +- ...llegal_service_and_process_control_via_mimikatz_modules.yml | 2 +- ...gal_service_and_process_control_via_powersploit_modules.yml | 2 +- ..._access_with_stolen_credentials_via_powersploit_modules.yml | 2 +- .../endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml | 2 +- .../endpoint/ssa___rare_parent_process_relationship_lolbas.yml | 2 +- ...s_and_persistence_opportunities_via_powersploit_modules.yml | 2 +- ...nd_use_accounts_groups_policies_via_powersploit_modules.yml | 2 +- ...sa___recon_and_use_accounts_groups_via_mimikatz_modules.yml | 2 +- ...active_directory_infrastructure_via_powersploit_modules.yml | 2 +- ...recon_and_use_computers_domains_via_powersploit_modules.yml | 2 +- .../ssa___recon_and_use_computers_via_mimikatz_modules.yml | 2 +- ...d_use_operating_system_elements_via_powersploit_modules.yml | 2 +- .../ssa___recon_and_use_shares_via_mimikatz_modules.yml | 2 +- .../ssa___recon_and_use_shares_via_powersploit_modules.yml | 2 +- .../ssa___recon_connectivity_via_powersploit_modules.yml | 2 +- ...con_credential_stores_and_services_via_mimikatz_modules.yml | 2 +- .../ssa___recon_defensive_tools_via_powersploit_modules.yml | 2 +- ...vilege_escalation_opportunities_via_powersploit_modules.yml | 2 +- ...___recon_process_service_hijacking_via_mimikatz_modules.yml | 2 +- ...ssa___recon_processes_and_services_via_mimikatz_modules.yml | 2 +- .../ssa___setting_credentials_via_dsinternals_modules.yml | 2 +- .../ssa___setting_credentials_via_mimikatz_modules.yml | 2 +- .../ssa___setting_credentials_via_powersploit_modules.yml | 2 +- .../ssa___system_process_running_unexpected_location.yml | 2 +- .../endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml | 2 +- detections/endpoint/ssa___unusually_long_command_line.yml | 2 +- .../endpoint/suspicious_microsoft_workflow_compiler_rename.yml | 2 +- .../endpoint/suspicious_microsoft_workflow_compiler_usage.yml | 3 ++- detections/endpoint/suspicious_msbuild_path.yml | 3 ++- detections/endpoint/suspicious_msbuild_rename.yml | 2 +- detections/endpoint/suspicious_msbuild_spawn.yml | 3 ++- detections/endpoint/suspicious_mshta_child_process.yml | 3 ++- detections/endpoint/suspicious_mshta_spawn.yml | 3 ++- detections/endpoint/suspicious_reg_exe_process.yml | 2 +- detections/endpoint/suspicious_wevtutil_usage.yml | 3 ++- .../endpoint/suspicious_writes_to_windows_recycle_bin.yml | 2 +- detections/endpoint/system_information_discovery_detection.yml | 3 ++- .../system_processes_run_from_unexpected_locations.yml | 2 +- detections/endpoint/unload_sysmon_filter_driver.yml | 3 ++- detections/endpoint/unusually_long_command_line.yml | 2 +- detections/endpoint/unusually_long_command_line___mltk.yml | 2 +- detections/endpoint/usn_journal_deletion.yml | 3 ++- detections/endpoint/wbadmin_delete_system_backups.yml | 3 ++- detections/endpoint/windows_adfind_exe.yml | 3 ++- detections/endpoint/windows_event_log_cleared.yml | 2 +- .../endpoint/windows_security_account_manager_stopped.yml | 2 +- .../endpoint/wmi_permanent_event_subscription___sysmon.yml | 2 +- .../application/detect_new_login_attempts_to_routers.yml | 3 ++- .../experimental/application/detect_phishing_content___ssa.yml | 2 +- .../application/email_attachments_with_lots_of_spaces.yml | 3 ++- .../email_servers_sending_high_volume_traffic_to_hosts.yml | 3 ++- .../experimental/application/monitor_email_for_brand_abuse.yml | 3 ++- .../application/no_windows_updates_in_a_time_frame.yml | 3 ++- .../application/spectre_and_meltdown_vulnerable_systems.yml | 3 ++- .../application/suspicious_email___uba_anomaly.yml | 3 ++- .../application/suspicious_email_attachment_extensions.yml | 3 ++- .../experimental/application/suspicious_java_classes.yml | 2 +- .../cloud/amazon_eks_kubernetes_cluster_scan_detection.yml | 2 +- .../cloud/amazon_eks_kubernetes_pod_scan_detection.yml | 2 +- .../experimental/cloud/aws_detect_attach_to_role_policy.yml | 2 +- .../experimental/cloud/aws_detect_permanent_key_creation.yml | 2 +- detections/experimental/cloud/aws_detect_role_creation.yml | 2 +- .../experimental/cloud/aws_detect_sts_assume_role_abuse.yml | 2 +- .../cloud/aws_detect_sts_get_session_token_abuse.yml | 2 +- .../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 2 +- detections/experimental/cloud/gcp_detect_gcploit_framework.yml | 2 +- ...cp_detect_high_risk_permissions_by_resource_and_account.yml | 2 +- detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml | 2 +- .../cloud/gcp_kubernetes_cluster_pod_scan_detection.yml | 2 +- .../cloud/gcp_kubernetes_cluster_scan_detection.yml | 2 +- ...bernetes_aws_detect_most_active_service_accounts_by_pod.yml | 2 +- .../kubernetes_aws_detect_rbac_authorizations_by_account.yml | 2 +- .../cloud/kubernetes_aws_detect_sensitive_object_access.yml | 2 +- .../cloud/kubernetes_aws_detect_sensitive_role_access.yml | 2 +- ...es_aws_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml | 2 +- ...re_detect_most_active_service_accounts_by_pod_namespace.yml | 2 +- .../kubernetes_azure_detect_rbac_authorization_by_account.yml | 2 +- .../cloud/kubernetes_azure_detect_sensitive_object_access.yml | 2 +- .../cloud/kubernetes_azure_detect_sensitive_role_access.yml | 2 +- ..._azure_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml | 2 +- .../cloud/kubernetes_azure_pod_scan_fingerprint.yml | 2 +- .../experimental/cloud/kubernetes_azure_scan_fingerprint.yml | 2 +- .../kubernetes_gcp_detect_RBAC_authorizations_by_account.yml | 2 +- ...bernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 2 +- .../cloud/kubernetes_gcp_detect_sensitive_object_access.yml | 2 +- .../cloud/kubernetes_gcp_detect_sensitive_role_access.yml | 2 +- ...es_gcp_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 2 +- .../experimental/endpoint/child_processes_of_spoolsv_exe.yml | 3 ++- .../endpoint/detect_baron_samedit_cve_2021_3156.yml | 2 +- .../endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml | 2 +- .../detect_baron_samedit_cve_2021_3156_via_osquery.yml | 2 +- .../endpoint/detect_oulook_exe_writing_a__zip_file.yml | 2 +- .../endpoint/detection_of_tools_built_by_nirsoft.yml | 3 ++- .../endpoint/first_time_seen_running_windows_service.yml | 2 +- .../experimental/endpoint/macos___re_opened_applications.yml | 3 ++- .../endpoint/processes_tapping_keyboard_events.yml | 2 +- .../endpoint/remote_desktop_process_running_on_system.yml | 3 ++- detections/experimental/endpoint/spike_in_file_writes.yml | 2 +- .../endpoint/sunburst_correlation_dll_and_network_event.yml | 2 +- .../experimental/endpoint/wmi_permanent_event_subscription.yml | 2 +- .../experimental/endpoint/wmi_temporary_event_subscription.yml | 2 +- detections/experimental/network/detect_arp_poisoning.yml | 2 +- detections/experimental/network/dns_record_changed.yml | 3 ++- detections/experimental/network/excessive_dns_failures.yml | 3 ++- ...eiving_high_volume_of_network_traffic_from_email_server.yml | 3 ++- .../experimental/network/large_volume_of_dns_any_queries.yml | 3 ++- .../network/prohibited_network_traffic_allowed.yml | 3 ++- detections/experimental/network/protocol_or_port_mismatch.yml | 3 ++- .../network/protocols_passing_authentication_in_cleartext.yml | 3 ++- .../detect_attackers_scanning_for_vulnerable_jboss_servers.yml | 3 ++- .../experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml | 2 +- .../web/detect_malicious_requests_to_exploit_jboss_servers.yml | 3 ++- .../experimental/web/monitor_web_traffic_for_brand_abuse.yml | 3 ++- detections/experimental/web/sql_injection_with_long_urls.yml | 3 ++- detections/experimental/web/supernova_webshell.yml | 3 ++- .../detect_hosts_connecting_to_dynamic_domain_providers.yml | 3 ++- .../network/detect_ipv6_network_infrastructure_threats.yml | 2 +- detections/network/detect_large_outbound_icmp_packets.yml | 3 ++- detections/network/detect_outbound_smb_traffic.yml | 3 ++- detections/network/detect_port_security_violation.yml | 2 +- detections/network/detect_rogue_dhcp_server.yml | 2 +- detections/network/detect_snicat_sni_exfiltration.yml | 2 +- .../network/detect_software_download_to_network_device.yml | 3 ++- detections/network/detect_traffic_mirroring.yml | 2 +- .../network/detect_unauthorized_assets_by_mac_address.yml | 3 ++- .../network/detect_windows_dns_sigred_via_splunk_stream.yml | 2 +- detections/network/detect_windows_dns_sigred_via_zeek.yml | 3 ++- detections/network/detect_zerologon_via_zeek.yml | 2 +- detections/network/dns_query_length_outliers___mltk.yml | 3 ++- .../network/dns_query_length_with_high_standard_deviation.yml | 3 ++- detections/network/remote_desktop_network_bruteforce.yml | 3 ++- detections/network/remote_desktop_network_traffic.yml | 3 ++- detections/network/smb_traffic_spike.yml | 3 ++- detections/network/smb_traffic_spike___mltk.yml | 3 ++- detections/network/tor_traffic.yml | 3 ++- detections/network/unusually_long_content_type_length.yml | 2 +- detections/web/web_fraud___account_harvesting.yml | 2 +- detections/web/web_fraud___anomalous_user_clickspeed.yml | 2 +- .../web/web_fraud___password_sharing_across_accounts.yml | 2 +- 337 files changed, 473 insertions(+), 337 deletions(-) diff --git a/detections/application/email_files_written_outside_of_the_outlook_directory.yml b/detections/application/email_files_written_outside_of_the_outlook_directory.yml index 1c41e653c6..cf6aed99a7 100644 --- a/detections/application/email_files_written_outside_of_the_outlook_directory.yml +++ b/detections/application/email_files_written_outside_of_the_outlook_directory.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks at the change-analysis data model and detects email files created outside the normal Outlook directory. search: '| tstats `security_content_summariesonly` count values(Filesystem.file_path) diff --git a/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml b/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml index 68212d5645..c5d3cf32e1 100644 --- a/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml +++ b/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects Okta login failures due to bad credentials for multiple users originating from the same ip address. search: '`okta` outcome.reason=INVALID_CREDENTIALS | rename client.geographicalContext.country diff --git a/detections/application/okta_account_lockout_events.yml b/detections/application/okta_account_lockout_events.yml index 82a6c703a6..0740c2cf38 100644 --- a/detections/application/okta_account_lockout_events.yml +++ b/detections/application/okta_account_lockout_events.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: Detect Okta user lockout events search: '`okta` displayMessage="Max sign in attempts exceeded" | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city diff --git a/detections/application/okta_failed_sso_attempts.yml b/detections/application/okta_failed_sso_attempts.yml index 584477eebb..8b5426dcc9 100644 --- a/detections/application/okta_failed_sso_attempts.yml +++ b/detections/application/okta_failed_sso_attempts.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: Detect failed Okta SSO events search: '`okta` displayMessage="User attempted unauthorized access to app" | stats min(_time) as firstTime max(_time) as lastTime values(app) as Apps count by user, result ,displayMessage, diff --git a/detections/application/okta_user_logins_from_multiple_cities.yml b/detections/application/okta_user_logins_from_multiple_cities.yml index 6805d5819e..80a5e47e0b 100644 --- a/detections/application/okta_user_logins_from_multiple_cities.yml +++ b/detections/application/okta_user_logins_from_multiple_cities.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects logins from the same user from different states in a 24 hour period. search: '`okta` displayMessage="User login to Okta" client.geographicalContext.city!=null diff --git a/detections/application/web_servers_executing_suspicious_processes.yml b/detections/application/web_servers_executing_suspicious_processes.yml index 71200c379d..b9cceaa60a 100644 --- a/detections/application/web_servers_executing_suspicious_processes.yml +++ b/detections/application/web_servers_executing_suspicious_processes.yml @@ -4,7 +4,8 @@ version: 1 date: '2019-04-01' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for suspicious processes on all systems labeled as web servers. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/cloud/abnormally_high_cloud_instances_destroyed.yml b/detections/cloud/abnormally_high_cloud_instances_destroyed.yml index 22e02367e6..c8df0ab4a6 100644 --- a/detections/cloud/abnormally_high_cloud_instances_destroyed.yml +++ b/detections/cloud/abnormally_high_cloud_instances_destroyed.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-08-21' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search finds for the number successfully destroyed cloud instances for every 4 hour block. This is split up between weekdays and the weekend. It then applies the probability densitiy model previously created and alerts on any outliers. diff --git a/detections/cloud/abnormally_high_cloud_instances_launched.yml b/detections/cloud/abnormally_high_cloud_instances_launched.yml index 1a0d746484..707441011f 100644 --- a/detections/cloud/abnormally_high_cloud_instances_launched.yml +++ b/detections/cloud/abnormally_high_cloud_instances_launched.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-08-21' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search finds for the number successfully created cloud instances for every 4 hour block. This is split up between weekdays and the weekend. It then applies the probability densitiy model previously created and alerts on any outliers. diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 0f65db13e6..c1ff376df3 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-09-07' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search will detect a spike in the number of API calls made to your cloud infrastructure environment by a user. search: '| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 1095e9a7cf..d0d3e0896f 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-09-07' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search will detect a spike in the number of API calls made to your cloud infrastructure environment about security groups by a user. search: '| tstats count as security_group_api_calls values(All_Changes.command) as diff --git a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml index 7e69adf812..031dc0314f 100644 --- a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml +++ b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-05-28' author: Rico Valdez, Splunk type: batch -datamodel: Authentication +datamodel: +- Authentication description: This search looks for AssumeRole events where an IAM role in a different account is requested for the first time. This search is deprecated and have been translated to use the latest Authentication Datamodel. diff --git a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 3a7692c67e..a4908609fa 100644 --- a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-11' author: Rod Soto, Patrick Bareiss Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of KMS keys which action kms:Encrypt is accessible for everyone (also outside of your organization). This is an identicator that your account is compromised and the attacker uses the encryption key to compromise diff --git a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml index a8a01ae4e9..4d6aa650a2 100644 --- a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml +++ b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-11' author: Rod Soto, Patrick Bareiss Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of users with KMS keys performing encryption specifically against S3 buckets. search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index 4330785494..d7139b27ac 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -4,7 +4,7 @@ version: 2 date: '2021-01-11' author: Bhavin Patel, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR. search: '`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 33b25f0de6..8e46d7d836 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -4,7 +4,7 @@ version: 2 date: '2021-01-12' author: Bhavin Patel, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the AWS console by compromising an admin account, they can diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index 583086c3d2..6df67d5086 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-09-04' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for new commands from each user role. search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where All_Changes.user_type=AssumedRole AND All_Changes.status=success by All_Changes.user, diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index ad3c3915c3..3d7badf4fb 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-08-21' author: Rico Valdez, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud compute instances created by users who have not created them before. search: '| tstats `security_content_summariesonly` count earliest(_time) as firstTime, diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 06524b6337..978fde7bf0 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-09-02' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks at cloud-infrastructure events where an instance is created in any region within the last hour and then compares it to a lookup file of previously seen regions where instances have been created. diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index b91c12d76d..d0929d8ea7 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -4,7 +4,8 @@ version: 1 date: '2018-10-12' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud compute instances being created with previously unseen image IDs. search: '| tstats count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index ec1232c365..4aeac30448 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-09-12' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: Find EC2 instances being created with previously unseen instance types. search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.instance_type, diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index aae7fc7feb..aa780adff6 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-07-29' author: Rico Valdez, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud instances being modified by users who have not previously modified them. search: '| tstats `security_content_summariesonly` count earliest(_time) as firstTime, diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index 623093bb0b..8c643b706c 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-09' author: Rico Valdez, Bhavin Patel, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that runs or creates something. diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index a805a550c9..fbb48af47f 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-09' author: Rico Valdez, Bhavin Patel, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that runs or creates something. diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index d6b662bd2c..e509bcbc4a 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-08-16' author: Rico Valdez, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that runs or creates something. diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index c1574a9be7..20f142f9ab 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-08-16' author: Rico Valdez, Bhavin Patel, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search looks for cloud provisioning activities from previously unseen regions. Provisioning activities are defined broadly as any event that runs or creates something. diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index 5330520d4e..0aafdb8a6d 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-05-28' author: Rico Valdez, Splunk type: batch -datamodel: Authentication +datamodel: +- Authentication description: This search looks for CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index ac6b0a8bd9..f1da78bdcd 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-07' author: Bhavin Patel, Splunk type: batch -datamodel: Authentication +datamodel: +- Authentication description: This search looks for CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index b88168e79b..49329e47c4 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-07' author: Bhavin Patel, Splunk type: batch -datamodel: Authentication +datamodel: +- Authentication description: This search looks for CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index 813670e2f3..965ab4d574 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-07' author: Bhavin Patel, Splunk type: batch -datamodel: Authentication +datamodel: +- Authentication description: This search looks for CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. diff --git a/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml b/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml index 047817dc25..d5a702a1cb 100644 --- a/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml +++ b/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-10' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks at GCP Storage bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed a GCP Storage bucket. diff --git a/detections/cloud/detect_new_open_gcp_storage_buckets.yml b/detections/cloud/detect_new_open_gcp_storage_buckets.yml index 05a2b746cc..cb8dfcf3fe 100644 --- a/detections/cloud/detect_new_open_gcp_storage_buckets.yml +++ b/detections/cloud/detect_new_open_gcp_storage_buckets.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-05' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for GCP PubSub events where a user has created an open/public GCP Storage bucket. search: '`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions diff --git a/detections/cloud/detect_new_open_s3_buckets.yml b/detections/cloud/detect_new_open_s3_buckets.yml index b72952640f..7de7edd00e 100644 --- a/detections/cloud/detect_new_open_s3_buckets.yml +++ b/detections/cloud/detect_new_open_s3_buckets.yml @@ -4,7 +4,7 @@ version: 2 date: '2021-01-12' author: Bhavin Patel, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where a user has created an open/public S3 bucket. search: '`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl | rex field=_raw diff --git a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml index 2144ea2cc2..83af071e38 100644 --- a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml +++ b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-12' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where a user has created an open/public S3 bucket over the aws cli. search: '`cloudtrail` eventSource="s3.amazonaws.com" eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp diff --git a/detections/cloud/detect_s3_access_from_a_new_ip.yml b/detections/cloud/detect_s3_access_from_a_new_ip.yml index ddc1308ca9..3cf6e5e656 100644 --- a/detections/cloud/detect_s3_access_from_a_new_ip.yml +++ b/detections/cloud/detect_s3_access_from_a_new_ip.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-06-28' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks at S3 bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed an S3 bucket. search: '`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200 diff --git a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml index af2ca63234..63666bec2c 100644 --- a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml +++ b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml @@ -4,7 +4,7 @@ version: 3 date: '2021-01-26' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals search: '`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance | bucket span=4h diff --git a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml index ad6779e610..a2cbabf3fe 100644 --- a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml +++ b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml @@ -4,7 +4,7 @@ version: 3 date: '2021-01-26' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for a spike in number of of AWS security Hub alerts for an AWS IAM User in 4 hours intervals. search: '`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser | rename diff --git a/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml b/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml index 12b6faa698..fbc6eef691 100644 --- a/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml +++ b/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-05-07' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search will detect spike in blocked outbound network connections originating from within your AWS environment. It will also update the cache file that factors in the latest data. diff --git a/detections/cloud/detect_spike_in_s3_bucket_deletion.yml b/detections/cloud/detect_spike_in_s3_bucket_deletion.yml index 5eea45dfe0..e43dd157f8 100644 --- a/detections/cloud/detect_spike_in_s3_bucket_deletion.yml +++ b/detections/cloud/detect_spike_in_s3_bucket_deletion.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-11-27' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects users creating spikes in API activity related to deletion of S3 buckets in your AWS environment. It will also update the cache file that factors in the latest data. diff --git a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml index 9c1b8f633c..549076642f 100644 --- a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml +++ b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-16' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. diff --git a/detections/cloud/new_container_uploaded_to_aws_ecr.yml b/detections/cloud/new_container_uploaded_to_aws_ecr.yml index 8d84f2b0d7..0ce8471f56 100644 --- a/detections/cloud/new_container_uploaded_to_aws_ecr.yml +++ b/detections/cloud/new_container_uploaded_to_aws_ecr.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-02-20' author: Rod Soto, Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This searches show information on uploaded containers including source user, image id, source IP user type, http user agent, region, first time, last time of operation (PutImage). These searches are based on Cloud Infrastructure Data Model. diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml index f4007f9877..068ee74a67 100644 --- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml +++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-12' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects newly added IP addresses/CIDR blocks to the list of MFA Trusted IPs to bypass multi factor authentication. Attackers are often known to use this technique so that they can bypass the MFA system. diff --git a/detections/cloud/o365_disable_mfa.yml b/detections/cloud/o365_disable_mfa.yml index 302c14c05d..6f2bafe120 100644 --- a/detections/cloud/o365_disable_mfa.yml +++ b/detections/cloud/o365_disable_mfa.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-16' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects when multi factor authentication has been disabled, what entitiy performed the action and against what user search: '`o365_management_activity` Operation="Disable Strong Authentication." | stats diff --git a/detections/cloud/o365_excessive_authentication_failures_alert.yml b/detections/cloud/o365_excessive_authentication_failures_alert.yml index 69508d2f11..7bed02ff02 100644 --- a/detections/cloud/o365_excessive_authentication_failures_alert.yml +++ b/detections/cloud/o365_excessive_authentication_failures_alert.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-16' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects when an excessive number of authentication failures occur this search also includes attempts against MFA prompt codes search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* diff --git a/detections/cloud/o365_pst_export_alert.yml b/detections/cloud/o365_pst_export_alert.yml index 659c8fc0f3..ff9b4fdc02 100644 --- a/detections/cloud/o365_pst_export_alert.yml +++ b/detections/cloud/o365_pst_export_alert.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-16' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects when a user has performed an Ediscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content diff --git a/detections/cloud/o365_suspicious_admin_email_forwarding.yml b/detections/cloud/o365_suspicious_admin_email_forwarding.yml index b0086b6ef7..0b68dd9f0f 100644 --- a/detections/cloud/o365_suspicious_admin_email_forwarding.yml +++ b/detections/cloud/o365_suspicious_admin_email_forwarding.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-16' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Parameters diff --git a/detections/cloud/o365_suspicious_rights_delegation.yml b/detections/cloud/o365_suspicious_rights_delegation.yml index c8a746f7af..7c149be71d 100644 --- a/detections/cloud/o365_suspicious_rights_delegation.yml +++ b/detections/cloud/o365_suspicious_rights_delegation.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-15' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. search: '`o365_management_activity` Operation=Add-MailboxPermission | spath input=Parameters diff --git a/detections/cloud/o365_suspicious_user_email_forwarding.yml b/detections/cloud/o365_suspicious_user_email_forwarding.yml index 2b0a5ffbde..11df462b65 100644 --- a/detections/cloud/o365_suspicious_user_email_forwarding.yml +++ b/detections/cloud/o365_suspicious_user_email_forwarding.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-16' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects when multiple user configured a forwarding rule to the same destination. search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Parameters diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml index 22ea96c9bb..04a951ed8e 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml index 36d93256b0..1f65472313 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Jason Brewer, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml index 05246e8a1c..3a96f41ae8 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where an abnormally high number of instances were successfully terminated by a user in a 10-minute window. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml index 5f4d1fe8cb..da395bc609 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Jason Brewer, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where a user successfully terminates an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index edc6d91c55..cd02a37e25 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-16' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: 'This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 555c5c4b05..97a40cd24b 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-16' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: 'This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 7e53b21702..d143b96e1c 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-16' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: 'This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index be691c57dc..ed27f7f87a 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-16' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for AWS provisioning activities from previously unseen regions. Region in this context is similar to a state in the United States. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml index c086f3711a..20ba2b6cd7 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search allows you to identify the endpoints that have connected to more than five DNS servers and made DNS Queries over the time frame of the search. search: '| tstats `security_content_summariesonly` count, values(DNS.dest) AS dest diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml index c3f38d4493..5dad492a18 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-09-08' author: Peter Gael, Splunk type: batch -datamodel: '' +datamodel: [] description: Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the console by compromising an admin account, they can delete diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml index 0ea740245c..4946cd844b 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-05-17' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where a user logged into the AWS account, is making API calls and has not enabled Multi Factor authentication. Multi factor authentication adds a layer of security by forcing the users to type diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml index aea98ef961..8fe8f9abfb 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for successful CloudTrail activity by user accounts that are not listed in the identity table or `aws_service_accounts.csv`. It returns event names and count, as well as the first and last time a specific user or service diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index d5cb8fbd30..5119da220a 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search looks for DNS requests for phishing domains that are leveraging EvilGinx tools to mimic websites. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml index 3fe5d5703d..a8027e9689 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/detections/deprecated/detect_long_dns_txt_record_response.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search is used to detect attempts to use DNS tunneling, by calculating the length of responses to DNS TXT queries. Endpoints using DNS as a method of transmission for data exfiltration, command and control, or evasion of security controls can diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml index cefe58f3d0..e7185bc1ba 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-12-03' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code. diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml index 8f907ef3bd..545349814a 100644 --- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-02-27' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for PowerShell requesting privileges consistent with credential dumping. Deprecated, looks like things changed from a logging perspective. search: '`wineventlog_security` signature_id=4703 Process_Name=*powershell.exe | rex diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index 3078398031..6fb8d2bae1 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-04-16' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects new API calls that have either never been seen before or that have not been seen in the previous hour, where the identity type is `AssumedRole`. search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index 9d1b2a0d30..d3b28f5d3b 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml index f694c57e23..963b8cf9df 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search will detect users creating spikes of API activity in your AWS environment. It will also update the cache file that factors in the latest data. This search is deprecated and have been translated to use the latest Change diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml index 7f7a363d18..5af6a6f8a9 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-05-21' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search will detect users creating spikes in API activity related to network access-control lists (ACLs)in your AWS environment. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml index 4eaefe70ff..5ef191c32c 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/detections/deprecated/detect_spike_in_security_group_activity.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-04-18' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search will detect users creating spikes in API activity related to security groups in your AWS environment. It will also update the cache file that factors in the latest data. This search is deprecated and have been translated diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml index 01a88312b2..de91cb7658 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/detections/deprecated/detect_usb_device_insertion.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-11-27' author: Bhavin Patel, Splunk type: batch -datamodel: Change_Analysis +datamodel: +- Change_Analysis description: The search is used to detect hosts that generate Windows Event ID 4663 for successful attempts to write to or read from a removable storage and Event ID 4656 for failures, which occurs when a USB drive is plugged in. In this scenario diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml index 7e4f2f2753..6159f55813 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Web +datamodel: +- Web description: This search looks for web connections to dynamic DNS providers. search: '| tstats `security_content_summariesonly` count values(Web.url) as url min(_time) as firstTime from datamodel=Web where Web.status=200 by Web.src Web.dest Web.status diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml index 4eedd37a75..026ff56776 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/detections/deprecated/detection_of_dns_tunnels.yml @@ -4,7 +4,8 @@ version: 2 date: '2017-09-18' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search is used to detect DNS tunneling, by calculating the sum of the length of DNS queries and DNS answers. The search also filters out potential false positives by filtering out queries made to internal systems and the queries diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index 6db07ee08f..f469b44e0f 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search will detect DNS requests resolved by unauthorized DNS servers. Legitimate DNS servers should be identified in the Enterprise Security Assets and Identity Framework. diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml index 7d3a2651e5..007b8365b1 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for EC2 instances being modified by users who have not previously modified them. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml index 63608de724..650c4b7ded 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-02-23' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file of previously seen regions where an instance was started diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml index 881591566e..f3f035632a 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-03-12' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml index 938ad04dc8..96f2384d72 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-02-07' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml index 7a6b6383da..9174162343 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the latest Change Datamodel. diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml index 4d8fb16510..e55b5629a0 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-11-19' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for processes launched from files with at least five spaces in the name before the extension. This is typically done to obfuscate the file extension by pushing it outside of the default view. diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml index 5cfa40eac7..f6f4bd3b06 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-12' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search returns a list of hosts that have not successfully completed a backup in over a week. Deprecated because it's a infrastructure monitoring. search: '`netbackup` MESSAGE="Disk/Partition backup completed successfully." | stats diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml index 713d6a3023..4346379bcd 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/detections/deprecated/first_time_seen_command_line_argument.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) diff --git a/detections/deprecated/gcp_gcr_container_uploaded.yml b/detections/deprecated/gcp_gcr_container_uploaded.yml index c4448def42..7285447e7e 100644 --- a/detections/deprecated/gcp_gcr_container_uploaded.yml +++ b/detections/deprecated/gcp_gcr_container_uploaded.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-02-20' author: Rod Soto, Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search show information on uploaded containers including source user, account, action, bucket name event name, http user agent, message and destination path. diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml index bc1a865ec9..d061e8349b 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/detections/deprecated/identify_new_user_accounts.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-12' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This detection search will help profile user accounts in your environment by identifying newly created accounts that have been added to your network in the past week. diff --git a/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml b/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml index ef0a48048e..f25d7f22f3 100644 --- a/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml +++ b/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml @@ -4,7 +4,8 @@ version: 6 date: '2021-01-19' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for PowerShell processes started with a base64 encoded command-line passed to it, with parameters to modify the execution policy for the process, and those that prevent the display of an interactive prompt to the user. diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml index e1e0089036..192b397281 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-23' author: David Dorsey, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search looks for DNS requests for faux domains similar to the domains that you want to have monitored for abuse. search: '| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time) diff --git a/detections/deprecated/open_redirect_in_splunk_web.yml b/detections/deprecated/open_redirect_in_splunk_web.yml index 1c39f5af86..4de972c878 100644 --- a/detections/deprecated/open_redirect_in_splunk_web.yml +++ b/detections/deprecated/open_redirect_in_splunk_web.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-19' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search allows you to look for evidence of exploitation for CVE-2016-4859, the Splunk Open Redirect Vulnerability. search: index=_internal sourcetype=splunk_web_access return_to="/%09/*" | `open_redirect_in_splunk_web_filter` diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index a66512c03f..67af959905 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-01-29' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for ColdRoot events from the osx-attacks osquery pack. search: '| from datamodel Alerts.Alerts | search app=osquery:results (name=pack_osx-attacks_OSX_ColdRoot_RAT_Launchd OR name=pack_osx-attacks_OSX_ColdRoot_RAT_Files) | rename columns.path as path | diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml index 80b609a5f9..6194f8d3d8 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/detections/deprecated/processes_created_by_netsh.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-11-23' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for processes launching netsh.exe to execute various commands via the netsh command-line utility. Netsh.exe is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml index 21c560cb83..1a6704e33a 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/detections/deprecated/prohibited_software_on_endpoint.yml @@ -4,7 +4,8 @@ version: 2 date: '2019-10-11' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for applications on the endpoint that you have marked as prohibited. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index 9de43f6de7..b2c90e57cd 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -4,7 +4,8 @@ version: 2 date: '2019-02-27' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for command-line arguments used to hide a file or directory using the reg add command. search: '| tstats `security_content_summariesonly` values(Processes.process) as process diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml index 89e2c8c3ba..47303fd553 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/detections/deprecated/remote_registry_key_modifications.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-03-02' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search monitors for remote modifications to registry keys. search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) diff --git a/detections/deprecated/remote_wmi_command_attempt.yml b/detections/deprecated/remote_wmi_command_attempt.yml index 43e8a4a5ec..69fb12d968 100644 --- a/detections/deprecated/remote_wmi_command_attempt.yml +++ b/detections/deprecated/remote_wmi_command_attempt.yml @@ -4,7 +4,8 @@ version: 2 date: '2018-12-03' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for wmic.exe being launched with parameters to operate on remote systems. search: '| tstats `security_content_summariesonly` count values(Processes.process) diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index 2fde684e32..2890ec3d5d 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for flags passed to schtasks.exe on the command-line that indicate that task names related to the execution of Bad Rabbit ransomware were created or deleted. Deprecated because we already have a similar detection diff --git a/detections/deprecated/splunk_enterprise_information_disclosure.yml b/detections/deprecated/splunk_enterprise_information_disclosure.yml index ef6d63259f..41267e544d 100644 --- a/detections/deprecated/splunk_enterprise_information_disclosure.yml +++ b/detections/deprecated/splunk_enterprise_information_disclosure.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-06-14' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search allows you to look for evidence of exploitation for CVE-2018-11409, a Splunk Enterprise Information Disclosure Bug. search: index=_internal sourcetype=splunkd_ui_access server-info | search clientip!=127.0.0.1 diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml index 714c5cb7b3..5fd3eea554 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/detections/deprecated/suspicious_changes_to_file_associations.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-07-22' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for changes to registry values that control Windows file associations, executed by a process that is not typical for legitimate, routine changes to this area. diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml index 787647b4d6..e45332c7ac 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/detections/deprecated/suspicious_file_write.yml @@ -4,7 +4,7 @@ version: 3 date: '2019-04-25' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for files created with names that have been linked to malicious activity. search: '| tstats `security_content_summariesonly` count values(Filesystem.action) diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml index 0e223b562a..6008e6015c 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-22' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects writes to the 'System Volume Information' folder by something other than the System process. search: (`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Volume\ diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml index 14b3437c32..fd10c518ef 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/detections/deprecated/uncommon_processes_on_endpoint.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-22' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for applications on the endpoint that you have marked as uncommon. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml index 4c1639f16c..605f07b9ca 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-12-06' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects loading of unsigned images by LSASS. Deprecated because too noisy. search: '`sysmon` EventID=7 Image=*lsass.exe Signed=false | stats count min(_time) diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml index 28ee3a06bf..9ba02a3e78 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/detections/deprecated/unsuccessful_netbackup_backups.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-09-12' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search gives you the hosts where a backup was attempted and then failed. search: '`netbackup` | stats latest(_time) as latestTime by COMPUTERNAME, MESSAGE diff --git a/detections/deprecated/windows_connhost_exe_force_flag.yml b/detections/deprecated/windows_connhost_exe_force_flag.yml index 7897c13c49..b0918d7154 100644 --- a/detections/deprecated/windows_connhost_exe_force_flag.yml +++ b/detections/deprecated/windows_connhost_exe_force_flag.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Rod Soto, Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: 'The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and is often seen executed by the Ryuk Ransomware. DEPRECATED This event is actually diff --git a/detections/deprecated/windows_disableantispyware_reg.yml b/detections/deprecated/windows_disableantispyware_reg.yml index 2ad0bc5adc..bb43cc26ce 100644 --- a/detections/deprecated/windows_disableantispyware_reg.yml +++ b/detections/deprecated/windows_disableantispyware_reg.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-11-06' author: Rod Soto, Jose Hernandez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml index 486c39c918..3d6f01dce7 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/detections/deprecated/windows_hosts_file_modification.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-11-02' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for modifications to the hosts file on all Windows endpoints across your environment. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index 0967d7da3f..8e56001e02 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -4,7 +4,7 @@ version: 2 date: '2019-12-06' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: Detect memory dumping of the LSASS process. search: '`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR CallTrace=*dbghelp.dll* | stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index ffd25b3196..6b85704d5b 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -4,7 +4,8 @@ version: 6 date: '2020-11-03' author: Patrick Bareiss, Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Attempt to add a certificate to the certificate store search: '| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=*certutil* diff --git a/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index a6c962b0ad..a3db88ef9d 100644 --- a/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -4,7 +4,8 @@ version: 6 date: '2020-11-06' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Monitor for changes of the ExecutionPolicy in the registry to the values "unrestricted" or "bypass," which allows the execution of malicious scripts. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 2010563f98..aeda81bccd 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for attempts to stop security-related services on the endpoint. search: '| tstats `security_content_summariesonly` values(Processes.process) as process diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index 6290a7598e..073111e911 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -4,7 +4,8 @@ version: 4 date: '2019-12-02' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index f72681e60c..831414fdba 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -4,7 +4,8 @@ version: 1 date: '2018-12-14' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for a batch file (.bat) written to the Windows system directory tree. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 17ee356fc1..9677362866 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-12-21' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for flags passed to bcdedit.exe modifications to the built-in Windows error recovery boot configurations. This is typically used by ransomware to prevent recovery. diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index 56133071a7..ff222a7ad4 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-11-09' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for file modifications with extensions commonly used by Ransomware search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/common_ransomware_notes.yml b/detections/endpoint/common_ransomware_notes.yml index 11e73c97a2..0c5b056f77 100644 --- a/detections/endpoint/common_ransomware_notes.yml +++ b/detections/endpoint/common_ransomware_notes.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-11-09' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for files created with names matching those typically used in ransomware notes that tell the victim how to get their data back. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index a43674de22..a5ce2ba435 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for the creation of local administrator accounts using net.exe. search: '| tstats `security_content_summariesonly` count values(Processes.user) as diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index 128a464a6a..e6a41509ee 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for the creation or deletion of hidden shares using net.exe. search: '| tstats `security_content_summariesonly` count values(Processes.user) as diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index 47b9e1b152..f169cc8f10 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-12-06' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: Detect remote thread creation into LSASS consistent with credential dumping. search: '`sysmon` EventID=8 TargetImage=*lsass.exe | stats count min(_time) as firstTime max(_time) as lastTime by Computer, EventCode, TargetImage, TargetProcessId | rename diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index e58a150115..c5d3e7bf3a 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -4,7 +4,8 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Monitor for signs that Ntdsutil, Vssadmin, or Wmic has been used to create a shadow copy. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index cc7132339a..4beda2d029 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -4,7 +4,8 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search detects the use of wmic and Powershell to create a shadow copy. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index b4e8a94ba1..19a4843bc4 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -4,7 +4,8 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search detects credential dumping using copy command from a shadow copy. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index ce9ee228aa..120f0c6a62 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -4,7 +4,8 @@ version: 1 date: '2019-12-10' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search detects the creation of a symlink to a shadow copy. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 4e8c5b41c6..30bc424e63 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-11-09' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service. Wmic is an interface to the Windows Management Instrumentation. This search looks for either of these tools being used to delete shadow copies. diff --git a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml index d09fc8afda..059103aaf6 100644 --- a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml @@ -4,7 +4,7 @@ version: 5 date: '2020-10-15' author: Bhavin Patel, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. search: '`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp diff --git a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml b/detections/endpoint/detect_computer_changed_with_anonymous_account.yml index a535de9336..acc30daf08 100644 --- a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml +++ b/detections/endpoint/detect_computer_changed_with_anonymous_account.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-09-18' author: Rod Soto, Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for Event Code 4742 (Computer Change) or EventCode 4624 (An account was successfully logged on) with an anonymous account. search: '`wineventlog_security` EventCode=4624 OR EventCode=4742 TargetUserName="ANONYMOUS diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index 9a363faaff..731bfccaa9 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -4,7 +4,7 @@ version: 3 date: '2019-12-03' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for reading lsass memory consistent with credential dumping. search: '`sysmon` EventCode=10 TargetImage=*lsass.exe (GrantedAccess=0x1010 OR GrantedAccess=0x1410) diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index 8acf77ae34..042c679c5f 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-11-09' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search identifies endpoints that have caused a relatively high number of account lockouts in a short period. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index 23240dde73..d2cc17c408 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search detects user accounts that have been locked out a relatively high number of times in a short period. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 0d39ba018d..1418a13549 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -4,7 +4,8 @@ version: 5 date: '2021-01-20' author: Bhavin Patel, Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies "mshta.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. The search will return the first diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index 1898433cad..eb067a7225 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-20' author: Michael Haag, Splunk type: batch -datamodel: '' +datamodel: [] description: The following analytic identifies renamed instances of mshta.exe executing. Mshta.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. This analytic utilizes the internal name of the PE to identify if is the legitimate mshta diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 6cf9a1b490..7d03e42ed7 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-20' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This analytic identifies when Microsoft HTML Application Host (mshta.exe) utility is used to make remote http connections. Adversaries may use mshta.exe to proxy the download and execution of remote .hta files. The analytic identifies command diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index 41af42bf7e..0cb8e5f687 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-07-08' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for newly created accounts that have been elevated to local administrators. search: '`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Administrators) diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index b2952c9def..6c2692c202 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-03' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: 'The detection Detect Path Interception By Creation Of program exe is detecting the abuse of unquoted service paths, which is a popular technique for privilege escalation. ' diff --git a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml index f18e9b8aee..4792f6e0dc 100644 --- a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-11-10' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for fast execution of processes used for system network configuration discovery on the endpoint. search: '| tstats `security_content_summariesonly` count values(Processes.process) diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index dfb56898c6..509d2c5873 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-11-10' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for executions of cmd.exe spawned by a process that is often abused by attackers and that does not typically launch cmd.exe. search: '| tstats `security_content_summariesonly` count values(Processes.process) diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 98d5dd6152..1750a7346a 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-11-10' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for events where `PsExec.exe` is run with the `accepteula` flag in the command line. PsExec is a built-in Windows utility that enables you to execute processes on other systems. It is fully interactive for console applications. diff --git a/detections/endpoint/detect_rare_executables.yml b/detections/endpoint/detect_rare_executables.yml index 0b080dea3a..e3bb2315b3 100644 --- a/detections/endpoint/detect_rare_executables.yml +++ b/detections/endpoint/detect_rare_executables.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-03-16' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search will return a table of rare processes, the names of the systems running them, and the users who initiated each process. search: '| tstats `security_content_summariesonly` count values(Processes.dest) as diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index 2f5bba037a..0bf9d3d37a 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-20' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies "rundll32.exe" execution with inline protocol handlers. "JavaScript", "VBScript", and "About" are the only supported options when invoking HTA content directly on the command-line. This type of behavior diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index ecaa3b975a..d2323a96f4 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for the execution of the cscript.exe or wscript.exe processes, with a parent of cmd.exe. The search will return the count, the first and last time this execution was seen on a machine, the user, and the destination diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index a0efa6e435..51ba8ec145 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-11-18' author: David Dorsey, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for modifications to registry keys that control the enforcement of Windows User Account Control (UAC). search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index 142690b09e..0bae24dffb 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-02-21' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Detect the usage of comsvcs.dll for dumping the lsass process. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index ab663ac773..633473b006 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-11-18' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for processes launched from files that have double extensions in the file name. This is typically done to obscure the "real" file extension and make it appear as though the file being accessed is a data file, as opposed diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index d757af0a1d..1f28151793 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -4,7 +4,8 @@ version: 1 date: '2018-12-14' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for file writes with extensions consistent with a SamSam ransomware attack. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/first_time_seen_child_process_of_zoom.yml b/detections/endpoint/first_time_seen_child_process_of_zoom.yml index cb435cc225..ed2f96bb2f 100644 --- a/detections/endpoint/first_time_seen_child_process_of_zoom.yml +++ b/detections/endpoint/first_time_seen_child_process_of_zoom.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-05-20' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for child processes spawned by zoom.exe or zoom.us that has not previously been seen. search: '| tstats `security_content_summariesonly` min(_time) as firstTime values(Processes.parent_process_name) diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index 933fef503a..04875404b5 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Attackers leverage an existing Windows binary, attrib.exe, to mark specific as hidden by using specific flags so that the victim does not see the file. The search looks for specific command-line arguments to detect the use of attrib.exe diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index bbc5a7289a..68e3409ef1 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-10-16' author: Jose Hernandez, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects a potential kerberoasting attack via service principal name requests search: '`wineventlog_security` EventCode=4769 Ticket_Options=0x40810000 Ticket_Encryption_Type=0x17 diff --git a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml index 14d1bcfd2d..1ca64442d6 100644 --- a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-11-20' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for PowerShell processes started with parameters to modify the execution policy of the run, run in a hidden window, and connect to the Internet. This combination of command-line options is suspicious because it's overriding diff --git a/detections/endpoint/malicious_powershell_process___encoded_command.yml b/detections/endpoint/malicious_powershell_process___encoded_command.yml index 08ce427bed..ae5c7cde68 100644 --- a/detections/endpoint/malicious_powershell_process___encoded_command.yml +++ b/detections/endpoint/malicious_powershell_process___encoded_command.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for PowerShell processes that have encoded the script within the command-line. Malware has been seen using this parameter, as it obfuscates the code and makes it relatively easy to pass a script on the command-line. diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index dd46fafd75..ce4c1b25d8 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for PowerShell processes started with parameters used to bypass the local execution policy for scripts. These parameters are often observed in attacks leveraging PowerShell scripts as they override the default PowerShell diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index 0970143462..84b9ad0d70 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -4,7 +4,8 @@ version: 4 date: '2021-01-19' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for PowerShell processes launched with arguments that have characters indicative of obfuscation on the command-line. search: '| tstats `security_content_summariesonly` count values(Processes.process) diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index 8c00d1684e..2f6f28ea94 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-11-23' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for registry activity associated with modifications to the registry key `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors`. In this scenario, an attacker can load an arbitrary .dll into the print-monitor registry diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index 742efeeb56..86d04768fb 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-25' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for the execution of `nltest.exe` with command-line arguments utilized to query for Domain Trust information. Two arguments `/domain trusts`, returns a list of trusted domains, and `/all_trusts`, returns all trusted diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index 5a672f6e56..f7d474c40e 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Microsoft Windows contains accessibility features that can be launched with a key combination before a user has logged in. An adversary can modify or replace these programs so they can get a command prompt or backdoor without logging in to diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index b7c5fdc258..59f617e43c 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -4,7 +4,7 @@ version: 4 date: '2021-01-28' author: Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for a process launching an `*.lnk` file under `C:\User*` or `*\Local\Temp\*`. This is common behavior used by various spear phishing tools. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index 5ef4307415..1de8f1b1ed 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-03-16' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for processes launched via WMI. search: '| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index f6f41d97fb..885bcbb14d 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-10' author: Josef Kuepker, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index 104cd85e4b..19210a288e 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-11-26' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for reg.exe modifying registry keys that define Windows services and their configurations. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index d9c6f3255e..84e1cd7d5d 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-11-26' author: Bhavin Patel, Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes. search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 184eca15cd..86e78d56ed 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -4,7 +4,7 @@ version: 5 date: '2020-11-27' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for modifications to registry keys that can be used to launch an application or service at system startup. search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 078361448e..54b17c7d6d 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-11-27' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for modifications to registry keys that can be used to elevate privileges. The registry keys under "Image File Execution Options" are used to intercept calls to an executable and can be used to attach malicious binaries diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index 5c0ad6b710..8730f187a9 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-11-30' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for wmic.exe being launched with parameters to spawn a process on a remote system. search: '| tstats `security_content_summariesonly` values(Processes.process) as process diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index 44479d6762..365530006f 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-11-30' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for executing scripts with rundll32. Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly, may avoid triggering security tools that may not monitor execution diff --git a/detections/endpoint/ryuk_test_files_detected.yml b/detections/endpoint/ryuk_test_files_detected.yml index d7466c1b3a..2b3e7386f4 100644 --- a/detections/endpoint/ryuk_test_files_detected.yml +++ b/detections/endpoint/ryuk_test_files_detected.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Rod Soto, Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for files that contain the key word *Ryuk* under any folder in the C drive, which is consistent with Ryuk propagation. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index 2ccc77bd08..19c7c97446 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -4,7 +4,8 @@ version: 1 date: '2018-12-14' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The search looks for a file named "test.txt" written to the windows system directory tree, which is consistent with Samsam propagation. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 76ed9d07f9..1d634d0a46 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for arguments to sc.exe indicating the creation or modification of a Windows service. search: '| tstats `security_content_summariesonly` values(Processes.process) as process diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index d759ae4a42..6041f950c7 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-12-17' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for flags passed to schtasks.exe on the command-line that indicate a task was created via command like. This has been associated with the Dragonfly threat actor, and the SUNBURST attack against Solarwinds. diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 69c154b30d..445e44861c 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for flags passed to schtasks.exe on the command-line that indicate a job is being scheduled on a remote system. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index fd1f4b8746..c6c443a99e 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-12-07' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled. search: '| tstats `security_content_summariesonly` values(Processes.process) as process diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index 05c5108822..f871561958 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-03-16' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for scripts launched via WMI. search: '| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index c92d3b42f7..942141552a 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-12-08' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for shim database files being written to default directories. The sdbinst.exe application is used to install shim database files (.sdb). According to Microsoft, a shim is a small library that transparently intercepts an API, changes diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 209718a88b..0ab6149713 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-11-23' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search detects the process execution and arguments required to silently create a shim database. The sdbinst.exe application is used to install shim database files (.sdb). A shim is a small library which transparently intercepts an API, changes diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 1974746428..01b6224326 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-06' author: David Dorsey, Splunk type: batch -datamodel: Change +datamodel: +- Change description: This search detects accounts that were created and deleted in a short time period. search: '| tstats `security_content_summariesonly` values(All_Changes.result_id) as diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index 5771fc65d2..b9e1602470 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-12-08' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for process names that consist only of a single letter. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest, Processes.user, diff --git a/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml index d75be2bf48..86fc6419ed 100644 --- a/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection indicates use of Mimikatz modules that facilitate Pass-the-Token attack, Golden or Silver kerberos ticket attack, and Skeleton key attack. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml index 00d886c605..76033240cc 100644 --- a/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Stolen credentials are applied by methods such as user impersonation, credential injection, spoofing of authentication processes or getting hold of critical accounts. This detection indicates such activities carried out by PowerSploit exploit diff --git a/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml b/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml index 425c10cc6f..a9fbfe364a 100644 --- a/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml +++ b/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of DSInternals modules that verify password strength, i.e., identify week accounts that would be easily compromised. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml index 3251782604..0d8fc65ffd 100644 --- a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml @@ -4,7 +4,7 @@ version: 1 date: 2020-6-04 author: Jose Hernandez, Splunk type: streaming -datamodel: '' +datamodel: [] description: Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, diff --git a/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml b/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml index 561517cd6b..10669bcbc2 100644 --- a/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml +++ b/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml @@ -5,7 +5,7 @@ version: 1 date: '2020-10-21' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals diff --git a/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml b/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml index 3452551d87..99d03f526a 100644 --- a/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml +++ b/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-21' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals diff --git a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml b/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml index 9770eb3b8a..9c8372ab3e 100644 --- a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml +++ b/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is diff --git a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml b/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml index baef60bfb9..deb6c19961 100644 --- a/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml +++ b/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is diff --git a/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml b/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml index 9106a02d17..312e52193e 100644 --- a/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml +++ b/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml @@ -5,7 +5,7 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit diff --git a/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml b/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml index 81c422de0e..e2bdad87a2 100644 --- a/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml +++ b/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. LaZagne is diff --git a/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml b/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml index 77ee8f0bd3..e0596efb21 100644 --- a/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml +++ b/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-21' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Mimikatz diff --git a/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml b/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml index f699d745c6..319a629ae4 100644 --- a/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml +++ b/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft diff --git a/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml b/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml index 50df426de3..f01749197a 100644 --- a/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml +++ b/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-18' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft diff --git a/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml b/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml index 6e6641f8f9..dd77c7a10e 100644 --- a/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml +++ b/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-21' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index 7423d70cf7..a216a7dac2 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-09-15' author: Jose Hernandez, Splunk type: streaming -datamodel: '' +datamodel: [] description: This search detects the memory of lsass.exe being dumped for offline credential theft attack. search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_event, diff --git a/detections/endpoint/ssa___detect_kerberoasting.yml b/detections/endpoint/ssa___detect_kerberoasting.yml index b5113e1907..c69e765be1 100644 --- a/detections/endpoint/ssa___detect_kerberoasting.yml +++ b/detections/endpoint/ssa___detect_kerberoasting.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-21' author: Xiao Lin, Splunk type: streaming -datamodel: '' +datamodel: [] description: This search detects a potential kerberoasting attack via service principal name requests search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), diff --git a/detections/endpoint/ssa___detect_pass_hash.yml b/detections/endpoint/ssa___detect_pass_hash.yml index 884b36a52e..5c8e01cdc4 100644 --- a/detections/endpoint/ssa___detect_pass_hash.yml +++ b/detections/endpoint/ssa___detect_pass_hash.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-21' author: Xiao Lin, Splunk type: streaming -datamodel: '' +datamodel: [] description: This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts using Pass-the-Hash technique. search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), diff --git a/detections/endpoint/ssa___first_time_seen_cmd_line.yml b/detections/endpoint/ssa___first_time_seen_cmd_line.yml index e47a5fe238..13dbb48ce4 100644 --- a/detections/endpoint/ssa___first_time_seen_cmd_line.yml +++ b/detections/endpoint/ssa___first_time_seen_cmd_line.yml @@ -4,7 +4,7 @@ version: 2 date: 2021-2-1 author: Ignacio Bermudez Corrales, Splunk type: streaming -datamodel: '' +datamodel: [] description: This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation on SPL2 of the rule `First time seen command line argument` by @bpatel. diff --git a/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml b/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml index 34e34e23c2..932ff82f8b 100644 --- a/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that enable illegaly access user content, such as key logging, audio recording, screenshots, tapping into http and RDP sessions, etc. diff --git a/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml b/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml index 53dbc1aac0..7295c87e80 100644 --- a/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that create accounts illegaly. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml b/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml index 5648763d5f..708b8caa17 100644 --- a/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml +++ b/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of DSInternals modules that enable or disable accounts illegaly. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml b/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml index 8b506ee660..801c3a48a3 100644 --- a/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that delete event logs. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml b/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml index c4c7e2f564..9cae8d5559 100644 --- a/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml +++ b/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml @@ -5,7 +5,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of DSInternals modules for illegal management of Active Directoty elements and policies. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml b/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml index 1ce01c8b13..b10f0022d7 100644 --- a/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml @@ -5,7 +5,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that enable illegal management of computers and Active Directory elements. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml index b454f8d158..5fca5d3491 100644 --- a/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that illegaly elevate general privileges or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent WMI, access to OS objects under desired identities. diff --git a/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml index bb05e7652e..dfc7caecd4 100644 --- a/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for illegal privilege elevation. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml index 16cb01f101..e48c0e2dc7 100644 --- a/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for illegal control over services and processes, including the authentication service. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml index a807811eb6..f4873171d8 100644 --- a/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-09' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that enable illegal control of services and processes, such as installing or spoofing of malicious services, injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, diff --git a/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml index 7666d455d5..49aabffa48 100644 --- a/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-04' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of PowerSploit modules that facilitate access probing with admin credentials as well as probing access to system services. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml b/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml index f80c64dcfe..51185fe9cb 100644 --- a/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml +++ b/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml @@ -4,7 +4,7 @@ version: 1 date: 2020-7-13 author: Ignacio Bermudez Corrales, Splunk type: streaming -datamodel: '' +datamodel: [] description: This search looks for executions of cmd.exe spawned by a process that is often abused by attackers and that does not typically launch cmd.exe. This is a SPL2 implementation of the rule `Detect Prohibited Applications Spawning cmd.exe` diff --git a/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml b/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml index 253069bd8e..cae920db5c 100644 --- a/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml +++ b/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-13' author: Ignacio Bermudez Corrales, Splunk type: streaming -datamodel: '' +datamodel: [] description: An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This search leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has diff --git a/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml index eb30b3a24b..c9e5137bbb 100644 --- a/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of PowerSploit modules that discover opportunities for malicious access and persistence. Some examples include access to admin accounts, weak access control policies, landing paths for dropping malicious software or data diff --git a/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml index 407061f458..3b17eac833 100644 --- a/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that discover accounts, groups and policies that can be accessed or taken over. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml index c2438624ad..2f883249b5 100644 --- a/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for discovery of accounts and groups and access to them. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml index 9cff7f42d9..79294b6bc3 100644 --- a/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml @@ -5,7 +5,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules for reconnaissance and access to elements of Active Directory infrastructure, such as domain identifiers, AD sites and forests, and trust relations. diff --git a/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml index 60026e7e39..85e186cde5 100644 --- a/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that discover computers, servers and domains that can be accessed or taken over. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml index bda6177eb0..8cd9d7b26b 100644 --- a/detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_computers_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for discovery of computers and servers and access to them. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml index 0604166ce0..943a54c3d8 100644 --- a/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that discover and access operating system elements, such as processes, services, registry locations, security packages and files. diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml index 0e60b19ad1..9e5d48b30b 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for discovery and access to network shares. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml index 7cd66cf817..585c65b3ab 100644 --- a/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules that discover and access network and distributed file system shares. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml index 02d8d9ffeb..fb6b7dc776 100644 --- a/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies access to PowerSploit modules for reconnaissance of connectivity. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml index 0b61c5b6d9..9acc663a70 100644 --- a/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies reconnaissance of credential stores and use of CryptoAPI services by Mimikatz modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml index 8a02f41b5d..c4c33b45d7 100644 --- a/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of PowerSploit modules for assessment of presence of defensive tools. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml b/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml index db276efaed..0bbbbd47da 100644 --- a/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of PowerSploit modules for assessment of privilege escalation opportunities. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml index f588d390af..131c82ca42 100644 --- a/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-05' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for discovery of process or service hijacking opportunities via Microsoft Detours compatibility. Microsoft Detours is an open source library for intercepting, monitoring and instrumenting diff --git a/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml b/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml index c7a76525d4..f6f89efba7 100644 --- a/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies use of Mimikatz modules for discovery and access to services and processes. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml b/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml index 40f872a226..d59251a5a9 100644 --- a/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml +++ b/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies illegal setting of credentials via DSInternals modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml b/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml index 803e852839..7e48a5013d 100644 --- a/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies illegal setting of credentials via Mimikatz modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml b/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml index f032996f9e..b06a294d1c 100644 --- a/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml +++ b/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-03' author: Stanislav Miskovic, Splunk type: streaming -datamodel: '' +datamodel: [] description: This detection identifies illegal setting of credentials via PowerSploit modules. search: '| from read_ssa_enriched_events() diff --git a/detections/endpoint/ssa___system_process_running_unexpected_location.yml b/detections/endpoint/ssa___system_process_running_unexpected_location.yml index 0d56f8d6dd..7dae442017 100644 --- a/detections/endpoint/ssa___system_process_running_unexpected_location.yml +++ b/detections/endpoint/ssa___system_process_running_unexpected_location.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-25' author: Ignacio Bermudez Corrales, Splunk type: streaming -datamodel: '' +datamodel: [] description: An attacker tries might try to use different version of a system command without overriding original, or they might try to avoid some detection running the process from a different folder. This detection checks that a list of system processes diff --git a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml index 65dbac3963..c12189596e 100644 --- a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml +++ b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-25' author: Ignacio Bermudez Corrales, Splunk type: streaming -datamodel: '' +datamodel: [] description: Attacker activity may compromise executing several LOLBAS applications in conjunction to accomplish their objectives. We are looking for more than usual LOLBAS applications over a window of time, by building profiles per machine. diff --git a/detections/endpoint/ssa___unusually_long_command_line.yml b/detections/endpoint/ssa___unusually_long_command_line.yml index 543471ae02..60b3d22433 100644 --- a/detections/endpoint/ssa___unusually_long_command_line.yml +++ b/detections/endpoint/ssa___unusually_long_command_line.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-06' author: Ignacio Bermudez Corrales, Splunk type: streaming -datamodel: '' +datamodel: [] description: Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin to help identify command lines with lengths that are unusual for a given user. This diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index b2ef1aed8b..4252a742a7 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-12' author: Michael Haag, Splunk type: batch -datamodel: '' +datamodel: [] description: The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml index 28d61d3d73..24cdd929a4 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-12' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies microsoft.workflow.compiler.exe usage. microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 2d29fea916..21360144b3 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-12' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies msbuild.exe executing from a non-standard path. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. Instances of Visual Studio diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 0966bfc877..d1144fcfc8 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-12' author: Michael Haag, Splunk type: batch -datamodel: '' +datamodel: [] description: The following analytic identifies renamed instances of msbuild.exe executing. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 9e52dff8c0..76fea9f03c 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-12' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavior is indicative of a COM object being utilized to spawn msbuild from wmiprvse.exe. It is common for MSBuild.exe to be spawned from devenv.exe while using diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index f7b2fc4896..5a9df018d5 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-12' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies child processes spawning from "mshta.exe". The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, parent process diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index 1b05083c24..1b379e204f 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-20' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior is indicative of a DCOM object being utilized to spawn mshta from wmiprvse.exe or svchost.exe. In this instance, adversaries may use LethalHTA that will spawn diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 5c2f9a78c2..0ac5e11eae 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-07-22' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for reg.exe being launched from a command prompt not started by the user. When a user launches cmd.exe, the parent process is usually explorer.exe. This search filters out those instances. diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 67fdb5c3d5..d38a7b7e54 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-22' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, or system event logs. diff --git a/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml b/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml index 7a644f0ed4..6336a4a2c5 100644 --- a/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml +++ b/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-07-22' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects writes to the recycle bin by a process other than explorer.exe. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index 65349ac57d..7ccc22413b 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-12' author: Patrick Bareiss, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Detect system information discovery techniques used by attackers to understand configurations of the system to further exploit it. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 41de7d0b97..7d96db24b9 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -4,7 +4,7 @@ version: 5 date: '2020-12-08' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for system processes that normally run out of C:\Windows\System32\ or C:\Windows\SysWOW64 that are not run from that location. This can indicate a malicious process that is trying to hide as a legitimate process. diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 612e561052..051223669f 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-22' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: Attackers often disable security tools to avoid detection. This search looks for the usage of process `fltMC.exe` to unload a Sysmon Driver that will stop sysmon from collecting the data. diff --git a/detections/endpoint/unusually_long_command_line.yml b/detections/endpoint/unusually_long_command_line.yml index f14c3a2d3e..f7d114d917 100644 --- a/detections/endpoint/unusually_long_command_line.yml +++ b/detections/endpoint/unusually_long_command_line.yml @@ -4,7 +4,7 @@ version: 5 date: '2020-12-08' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: Command lines that are extremely long may be indicative of malicious activity on your hosts. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/unusually_long_command_line___mltk.yml b/detections/endpoint/unusually_long_command_line___mltk.yml index b65af97359..458754720a 100644 --- a/detections/endpoint/unusually_long_command_line___mltk.yml +++ b/detections/endpoint/unusually_long_command_line___mltk.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-05-08' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Machine Learning Toolkit (MLTK) to help identify command lines with lengths that are unusual for a given user. diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index e304703539..b0a5d88e99 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -4,7 +4,8 @@ version: 2 date: '2018-12-03' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: The fsutil.exe application is a legitimate Windows utility used to perform tasks related to the file allocation table (FAT) and NTFS file systems. The update sequence number (USN) change journal provides a log of all changes made to the files diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index 5b2044f40f..5c47434d89 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-22' author: Michael Haag, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery. diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index cf4bc7270b..d83a5319bc 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-12-16' author: Jose Hernandez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: 'This search looks for the execution of `adfind.exe` with command-line arguments that it uses by default. Specifically the filter or search functions. It also considers the arguments necessary like objectcategory, see readme for more diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index 32fcf12fce..4551e47785 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-07-06' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for Windows events that indicate one of the Windows event logs has been purged. search: (`wineventlog_security` (EventCode=1102 OR EventCode=1100)) OR (`wineventlog_system` diff --git a/detections/endpoint/windows_security_account_manager_stopped.yml b/detections/endpoint/windows_security_account_manager_stopped.yml index 272c7aaea8..b0e0e01abf 100644 --- a/detections/endpoint/windows_security_account_manager_stopped.yml +++ b/detections/endpoint/windows_security_account_manager_stopped.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-11-06' author: Rod Soto, Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for a Windows Security Account Manager (SAM) was stopped via command-line. This is consistent with Ryuk infections across a fleet of endpoints. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml index 4f8be08104..bdf3982186 100644 --- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml +++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml @@ -4,7 +4,7 @@ version: 2 date: '2020-12-08' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for the creation of WMI permanent event subscriptions. search: '`sysmon` EventCode=21 | rename host as dest | table _time, dest, user, Operation, EventType, Query, Consumer, Filter | `wmi_permanent_event_subscription___sysmon_filter`' diff --git a/detections/experimental/application/detect_new_login_attempts_to_routers.yml b/detections/experimental/application/detect_new_login_attempts_to_routers.yml index 83288a1a8c..dcb8aa1b6b 100644 --- a/detections/experimental/application/detect_new_login_attempts_to_routers.yml +++ b/detections/experimental/application/detect_new_login_attempts_to_routers.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-12' author: Bhavin Patel, Splunk type: batch -datamodel: Authentication +datamodel: +- Authentication description: The search queries the authentication logs for assets that are categorized as routers in the ES Assets and Identity Framework, to identify connections that have not been seen before in the last 30 days. diff --git a/detections/experimental/application/detect_phishing_content___ssa.yml b/detections/experimental/application/detect_phishing_content___ssa.yml index 5f7014e4f9..9fc137905b 100644 --- a/detections/experimental/application/detect_phishing_content___ssa.yml +++ b/detections/experimental/application/detect_phishing_content___ssa.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-25' author: Xiao Lin, Splunk type: streaming -datamodel: '' +datamodel: [] description: Malicious mails can conduct phishing that induces readers to open attachment, click links or trigger third party service. This detect uses Natural Language Processing (NLP) approach to analyze an email message's content (Sender, Subject and Body) diff --git a/detections/experimental/application/email_attachments_with_lots_of_spaces.yml b/detections/experimental/application/email_attachments_with_lots_of_spaces.yml index 3279520ac2..b13ccb80ee 100644 --- a/detections/experimental/application/email_attachments_with_lots_of_spaces.yml +++ b/detections/experimental/application/email_attachments_with_lots_of_spaces.yml @@ -4,7 +4,8 @@ version: 2 date: '2017-09-19' author: David Dorsey, Splunk type: batch -datamodel: Email +datamodel: +- Email description: Attackers often use spaces as a means to obfuscate an attachment's file extension. This search looks for messages with email attachments that have many spaces within the file names. diff --git a/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml b/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml index bb0038362c..e829ed6c99 100644 --- a/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml +++ b/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for an increase of data transfers from your email server to your clients. This could be indicative of a malicious actor collecting data using your email server. diff --git a/detections/experimental/application/monitor_email_for_brand_abuse.yml b/detections/experimental/application/monitor_email_for_brand_abuse.yml index c30af1e322..b90a8c2d05 100644 --- a/detections/experimental/application/monitor_email_for_brand_abuse.yml +++ b/detections/experimental/application/monitor_email_for_brand_abuse.yml @@ -4,7 +4,8 @@ version: 2 date: '2018-01-05' author: David Dorsey, Splunk type: batch -datamodel: Email +datamodel: +- Email description: This search looks for emails claiming to be sent from a domain similar to one that you want to have monitored for abuse. search: '| tstats `security_content_summariesonly` values(All_Email.recipient) as diff --git a/detections/experimental/application/no_windows_updates_in_a_time_frame.yml b/detections/experimental/application/no_windows_updates_in_a_time_frame.yml index 242f56fcba..260866e37a 100644 --- a/detections/experimental/application/no_windows_updates_in_a_time_frame.yml +++ b/detections/experimental/application/no_windows_updates_in_a_time_frame.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-15' author: Bhavin Patel, Splunk type: batch -datamodel: Updates +datamodel: +- Updates description: This search looks for Windows endpoints that have not generated an event indicating a successful Windows update in the last 60 days. Windows updates are typically released monthly and applied shortly thereafter. An endpoint that has diff --git a/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml b/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml index b1cedc16e1..e68543b314 100644 --- a/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml +++ b/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-01-07' author: David Dorsey, Splunk type: batch -datamodel: Vulnerabilities +datamodel: +- Vulnerabilities description: The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) diff --git a/detections/experimental/application/suspicious_email___uba_anomaly.yml b/detections/experimental/application/suspicious_email___uba_anomaly.yml index 8d99063ded..55ce9bdb67 100644 --- a/detections/experimental/application/suspicious_email___uba_anomaly.yml +++ b/detections/experimental/application/suspicious_email___uba_anomaly.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-22' author: Bhavin Patel, Splunk type: batch -datamodel: UEBA +datamodel: +- UEBA description: This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA). diff --git a/detections/experimental/application/suspicious_email_attachment_extensions.yml b/detections/experimental/application/suspicious_email_attachment_extensions.yml index c78141c273..a5ddc04ec4 100644 --- a/detections/experimental/application/suspicious_email_attachment_extensions.yml +++ b/detections/experimental/application/suspicious_email_attachment_extensions.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-22' author: David Dorsey, Splunk type: batch -datamodel: Email +datamodel: +- Email description: This search looks for emails that have attachments with suspicious file extensions. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) diff --git a/detections/experimental/application/suspicious_java_classes.yml b/detections/experimental/application/suspicious_java_classes.yml index cf31dfc9a9..20b9f4c9a4 100644 --- a/detections/experimental/application/suspicious_java_classes.yml +++ b/detections/experimental/application/suspicious_java_classes.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-12-06' author: Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for suspicious Java classes that are often used to exploit remote command execution in common Java frameworks, such as Apache Struts. search: '`stream_http` http_method=POST http_content_length>1 | regex form_data="(?i)java\.lang\.(?:runtime|processbuilder)" diff --git a/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml b/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml index e4190cc8ea..17fc6b562d 100644 --- a/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml +++ b/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-15' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster in AWS search: '`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS diff --git a/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml b/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml index 15e8598bfb..7ec567a60c 100644 --- a/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml +++ b/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-15' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection information on unauthenticated requests against Kubernetes' Pods API search: '`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" verb=list objectRef.resource=pods diff --git a/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml b/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml index a2ec0facbe..ec33f24fd2 100644 --- a/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml +++ b/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-27' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of an user attaching itself to a different role trust policy. This can be used for lateral movement and escalation of privileges. search: '`aws_cloudwatchlogs_eks` attach policy| spath requestParameters.policyArn diff --git a/detections/experimental/cloud/aws_detect_permanent_key_creation.yml b/detections/experimental/cloud/aws_detect_permanent_key_creation.yml index 17363677d4..80b079210e 100644 --- a/detections/experimental/cloud/aws_detect_permanent_key_creation.yml +++ b/detections/experimental/cloud/aws_detect_permanent_key_creation.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-27' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of accounts creating permanent keys. Permanent keys are not created by default and they are only needed for programmatic calls. Creation of Permanent key is an important event to monitor. diff --git a/detections/experimental/cloud/aws_detect_role_creation.yml b/detections/experimental/cloud/aws_detect_role_creation.yml index 3687b0d7ac..1841b3f6e5 100644 --- a/detections/experimental/cloud/aws_detect_role_creation.yml +++ b/detections/experimental/cloud/aws_detect_role_creation.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-27' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of role creation by IAM users. Role creation is an event by itself if user is creating a new role with trust policies different than the available in AWS and it can be used for lateral movement and escalation diff --git a/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml b/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml index e3767be52d..99799e92b2 100644 --- a/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml +++ b/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-27' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of suspicious use of sts:AssumeRole. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. diff --git a/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml b/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml index b5782424bb..a3c5eb90ee 100644 --- a/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml +++ b/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-27' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of suspicious use of sts:GetSessionToken. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. diff --git a/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml index 358053810d..417e2f1a2c 100644 --- a/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-09' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges at different projects depending on organization schema. diff --git a/detections/experimental/cloud/gcp_detect_gcploit_framework.yml b/detections/experimental/cloud/gcp_detect_gcploit_framework.yml index a1c0dbad31..7d112319e1 100644 --- a/detections/experimental/cloud/gcp_detect_gcploit_framework.yml +++ b/detections/experimental/cloud/gcp_detect_gcploit_framework.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-08' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of GCPloit exploitation framework. This framework can be used to escalate privileges and move laterally from compromised high privilege accounts. diff --git a/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 4ed52576c3..e6f2d562b9 100644 --- a/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-09' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts to move laterally and escalate privileges. diff --git a/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml b/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml index c7fb7f77a2..78040c1056 100644 --- a/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml +++ b/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-09-01' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access sessions alive without further control of authentication, allowing attackers to diff --git a/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml b/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml index b1e002951e..09d4e4b55d 100644 --- a/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml +++ b/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-17' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster's pods search: '`google_gcp_pubsub_message` category=kube-audit |spath input=properties.log diff --git a/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml b/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml index e49171ebac..87ac299a8f 100644 --- a/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml +++ b/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-04-15' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster search: '`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerIp!=127.0.0.1 diff --git a/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 9ce356d05e..6db594f667 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision search: '`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts objectRef.resource=pods diff --git a/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml b/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml index 4f723b39d7..eb823b8f5b 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences diff --git a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml index 2f8ddb9a85..53741c5860 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets search: '`aws_cloudwatchlogs_eks` objectRef.resource=secrets OR configmaps sourceIPs{}!=::1 diff --git a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml index 15ad781918..26deca7fd1 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets search: '`aws_cloudwatchlogs_eks` objectRef.resource=clusterroles OR clusterrolebindings diff --git a/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 552cbac70a..36a83160fb 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source diff --git a/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml b/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml index 9be9a9eea4..ff8cba3f9e 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context search: '`aws_cloudwatchlogs_eks` userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 diff --git a/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml b/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml index f48d2d1228..df72e536e1 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-26' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | search diff --git a/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml index daecbadc5f..be00530427 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-26' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes of RBAC by accounts occurrences diff --git a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml index c107196f39..de93ee2c4f 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-20' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets search: '`kubernetes_azure` category=kube-audit | spath input=properties.log| search diff --git a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml index bbb4c2e527..fe1a6e62b9 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-20' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets search: '`kubernetes_azure` category=kube-audit | spath input=properties.log| search diff --git a/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index 5196ff3f46..c46ac27650 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-20' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes service accounts with failure or forbidden access status search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | search diff --git a/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml index 816d17d06c..2fa956e69c 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-26' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on rare Kubectl calls with IP, verb namespace and object access context search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | spath diff --git a/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml b/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml index 789f6aab81..3c337e5e26 100644 --- a/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml +++ b/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-20' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod in Azure diff --git a/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml b/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml index ee3aca11b0..287d0e96a1 100644 --- a/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml +++ b/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-05-19' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in Azure diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml b/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml index ffa22e5fe4..acfbad5842 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-11' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index 1547e991b5..df859c23a8 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-10' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision search: '`google_gcp_pubsub_message` data.protoPayload.request.spec.group{}=system:serviceaccounts diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml index 1e5916fc60..4c37d551b2 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-11' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets search: '`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.resource=configmaps diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml index f56f529ef5..aa3b1e3cac 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-11' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets search: '`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index a9d8488fa6..a05269a924 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-06-23' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index 434aa486ed..7123237ecf 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-11' author: Rod Soto, Splunk type: batch -datamodel: '' +datamodel: [] description: This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context search: '`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerSuppliedUserAgent=kubectl* diff --git a/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml b/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml index ba15ba0c80..21247f7933 100644 --- a/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml +++ b/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-03-16' author: Rico Valdez, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for child processes of spoolsv.exe. This activity is associated with a POC privilege-escalation exploit associated with CVE-2018-8440. Spoolsv.exe is the process associated with the Print Spooler service in Windows diff --git a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml index 8a9a7fd6d6..42553d4a4b 100644 --- a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml +++ b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-27' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects the heap-based buffer overflow of sudoedit search: '`linux_hosts` | search "sudoedit -s \\" | `detect_baron_samedit_cve_2021_3156_filter`' how_to_implement: Splunk Universal Forwarder running on Linux systems, capturing logs diff --git a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml index 482a5c3282..523180408b 100644 --- a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml +++ b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-29' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects the heap-based buffer overflow of sudoedit search: '`linux_hosts` | search sudoedit segfault | stats count min(_time) as firstTime max(_time) as lastTime by host | search count > 5 | `detect_baron_samedit_cve_2021_3156_segfault_filter`' diff --git a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml index 139a6d7071..bdaa20f495 100644 --- a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml +++ b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml @@ -4,7 +4,7 @@ version: 1 date: '2021-01-28' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects the heap-based buffer overflow of sudoedit search: '`osquery_process` | search "columns.cmdline"="sudoedit -s \\*" | `detect_baron_samedit_cve_2021_3156_via_osquery_filter`' how_to_implement: OSQuery installed and configured to pick up process events (info diff --git a/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml b/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml index b4e8c7514c..ed9e9b713a 100644 --- a/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml +++ b/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for execution of process `outlook.exe` where the process is writing a `.zip` file to the disk. search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) diff --git a/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml b/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml index f4a70da9ea..739c1d5904 100644 --- a/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml +++ b/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for specific command-line arguments that may indicate the execution of tools made by Nirsoft, which are legitimate, but may be abused by attackers. diff --git a/detections/experimental/endpoint/first_time_seen_running_windows_service.yml b/detections/experimental/endpoint/first_time_seen_running_windows_service.yml index a7b7d63200..4e96c879de 100644 --- a/detections/experimental/endpoint/first_time_seen_running_windows_service.yml +++ b/detections/experimental/endpoint/first_time_seen_running_windows_service.yml @@ -4,7 +4,7 @@ version: 4 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for the first and last time a Windows service is seen running in your environment. This table is then cached. search: '`wineventlog_system` EventCode=7036 | rex field=Message "The (?[-\(\)\s\w]+) diff --git a/detections/experimental/endpoint/macos___re_opened_applications.yml b/detections/experimental/endpoint/macos___re_opened_applications.yml index 5688d2c7f4..20dfa8b493 100644 --- a/detections/experimental/endpoint/macos___re_opened_applications.yml +++ b/detections/experimental/endpoint/macos___re_opened_applications.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-02-07' author: Jamie Windley, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for processes referencing the plist files that determine which applications are re-opened when a user reboots their machine. search: '| tstats `security_content_summariesonly` count values(Processes.process) diff --git a/detections/experimental/endpoint/processes_tapping_keyboard_events.yml b/detections/experimental/endpoint/processes_tapping_keyboard_events.yml index ef60bf5b43..d94c514f67 100644 --- a/detections/experimental/endpoint/processes_tapping_keyboard_events.yml +++ b/detections/experimental/endpoint/processes_tapping_keyboard_events.yml @@ -4,7 +4,7 @@ version: 1 date: '2019-01-25' author: Jose Hernandez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for processes in an MacOS system that is tapping keyboard events in MacOS, and essentially monitoring all keystrokes made by a user. This is a common technique used by RATs to log keystrokes from a victim, although it diff --git a/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml b/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml index f886104b2e..c00b9a83c9 100644 --- a/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml +++ b/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml @@ -4,7 +4,8 @@ version: 5 date: '2020-07-21' author: David Dorsey, Splunk type: batch -datamodel: Endpoint +datamodel: +- Endpoint description: This search looks for the remote desktop process mstsc.exe running on systems upon which it doesn't typically run. This is accomplished by filtering out all systems that are noted in the `common_rdp_source category` in the Assets and diff --git a/detections/experimental/endpoint/spike_in_file_writes.yml b/detections/experimental/endpoint/spike_in_file_writes.yml index 362df726e5..d8cdca1bb4 100644 --- a/detections/experimental/endpoint/spike_in_file_writes.yml +++ b/detections/experimental/endpoint/spike_in_file_writes.yml @@ -4,7 +4,7 @@ version: 3 date: '2020-03-16' author: David Dorsey, Splunk type: batch -datamodel: '' +datamodel: [] description: The search looks for a sharp increase in the number of files written to a particular host search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem diff --git a/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml b/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml index 39a1058908..fac0c15d6f 100644 --- a/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml +++ b/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-12-14' author: Patrick Bareiss, Splunk type: batch -datamodel: '' +datamodel: [] description: The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost.exe. After a period of 12-14 days, the malware will attempt to resolve a subdomain of avsvmcloud.com. This detections will correlate both events. diff --git a/detections/experimental/endpoint/wmi_permanent_event_subscription.yml b/detections/experimental/endpoint/wmi_permanent_event_subscription.yml index 1b9f4fe828..a35567f023 100644 --- a/detections/experimental/endpoint/wmi_permanent_event_subscription.yml +++ b/detections/experimental/endpoint/wmi_permanent_event_subscription.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-23' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for the creation of WMI permanent event subscriptions. search: '`wmi` EventCode=5861 Binding | rex field=Message "Consumer =\s+(?[^;|^$]+)" | search consumer!="NTEventLogEventConsumer=\"SCM Event Log Consumer\"" | stats diff --git a/detections/experimental/endpoint/wmi_temporary_event_subscription.yml b/detections/experimental/endpoint/wmi_temporary_event_subscription.yml index 1163296152..6ba11f0709 100644 --- a/detections/experimental/endpoint/wmi_temporary_event_subscription.yml +++ b/detections/experimental/endpoint/wmi_temporary_event_subscription.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-23' author: Rico Valdez, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for the creation of WMI temporary event subscriptions. search: '`wmi` EventCode=5860 Temporary | rex field=Message "NotificationQuery =\s+(?[^;|^$]+)" | search query!="SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = ''wsmprovhost.exe''" diff --git a/detections/experimental/network/detect_arp_poisoning.yml b/detections/experimental/network/detect_arp_poisoning.yml index 06fc67ecdd..0be208ae0e 100644 --- a/detections/experimental/network/detect_arp_poisoning.yml +++ b/detections/experimental/network/detect_arp_poisoning.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-11' author: Mikael Bjerkeland, Splunk type: batch -datamodel: '' +datamodel: [] description: By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organization's network devices, we will be able to detect ARP Poisoning attacks in the Infrastructure. diff --git a/detections/experimental/network/dns_record_changed.yml b/detections/experimental/network/dns_record_changed.yml index 3f5593e5d3..4815f3310d 100644 --- a/detections/experimental/network/dns_record_changed.yml +++ b/detections/experimental/network/dns_record_changed.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Jose Hernandez, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the Network_Resolution datamodel across the last day. diff --git a/detections/experimental/network/excessive_dns_failures.yml b/detections/experimental/network/excessive_dns_failures.yml index d03a705cc0..b000a4f436 100644 --- a/detections/experimental/network/excessive_dns_failures.yml +++ b/detections/experimental/network/excessive_dns_failures.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search identifies DNS query failures by counting the number of DNS responses that do not indicate success, and trigger on more than 50 occurrences. search: '| tstats `security_content_summariesonly` count values("DNS.query") as queries diff --git a/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml b/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml index 6bd14858a3..3f274315f2 100644 --- a/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml +++ b/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for an increase of data transfers from your email server to your clients. This could be indicative of a malicious actor collecting data using your email server. diff --git a/detections/experimental/network/large_volume_of_dns_any_queries.yml b/detections/experimental/network/large_volume_of_dns_any_queries.yml index 5eae7a35b1..2cd258a8fe 100644 --- a/detections/experimental/network/large_volume_of_dns_any_queries.yml +++ b/detections/experimental/network/large_volume_of_dns_any_queries.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-20' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: The search is used to identify attempts to use your DNS Infrastructure for DDoS purposes via a DNS amplification attack leveraging ANY queries. search: '| tstats `security_content_summariesonly` count from datamodel=Network_Resolution diff --git a/detections/experimental/network/prohibited_network_traffic_allowed.yml b/detections/experimental/network/prohibited_network_traffic_allowed.yml index 5f48155296..cae48f8216 100644 --- a/detections/experimental/network/prohibited_network_traffic_allowed.yml +++ b/detections/experimental/network/prohibited_network_traffic_allowed.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for network traffic defined by port and transport layer protocol in the Enterprise Security lookup table "lookup_interesting_ports", that is marked as prohibited, and has an associated 'allow' action in the Network_Traffic diff --git a/detections/experimental/network/protocol_or_port_mismatch.yml b/detections/experimental/network/protocol_or_port_mismatch.yml index 1f3f48b8d3..2b8ef78736 100644 --- a/detections/experimental/network/protocol_or_port_mismatch.yml +++ b/detections/experimental/network/protocol_or_port_mismatch.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Rico Valdez, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for network traffic on common ports where a higher layer protocol does not match the port that is being used. For example, this search should identify cases where protocols other than HTTP are running on TCP port 80. diff --git a/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml b/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml index 5decad1d46..5c54766ef7 100644 --- a/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml +++ b/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-11-04' author: Rico Valdez, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for cleartext protocols at risk of leaking credentials. Currently, this consists of legacy protocols such as telnet, POP3, IMAP, and non-anonymous FTP sessions. While some of these protocols can be used over SSL, they typically diff --git a/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml b/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml index 15159d0297..3c334a6a2e 100644 --- a/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml +++ b/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-23' author: Bhavin Patel, Splunk type: batch -datamodel: Web +datamodel: +- Web description: This search looks for specific GET or HEAD requests to web servers that are indicative of reconnaissance attempts to identify vulnerable JBoss servers. JexBoss is described as the exploit tool of choice for this malicious activity. diff --git a/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml b/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml index 22a0ab522c..f93c6322cc 100644 --- a/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml +++ b/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-02' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traffix SDC devices search: '`f5_bigip_rogue` | regex _raw="(hsqldb;|.*\\.\\.;.*)" | search `detect_f5_tmui_rce_cve_2020_5902_filter`' diff --git a/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml b/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml index 0930f90f6d..71bd1b6b3c 100644 --- a/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml +++ b/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-23' author: Bhavin Patel, Splunk type: batch -datamodel: Web +datamodel: +- Web description: This search is used to detect malicious HTTP requests crafted to exploit jmx-console in JBoss servers. The malicious requests have a long URL length, as the payload is embedded in the URL. diff --git a/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml b/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml index 57e84ac655..d00edff771 100644 --- a/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml +++ b/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-23' author: David Dorsey, Splunk type: batch -datamodel: Web +datamodel: +- Web description: This search looks for Web requests to faux domains similar to the one that you want to have monitored for abuse. search: '| tstats `security_content_summariesonly` values(Web.url) as urls min(_time) diff --git a/detections/experimental/web/sql_injection_with_long_urls.yml b/detections/experimental/web/sql_injection_with_long_urls.yml index 3336635cb9..7007b3a0a9 100644 --- a/detections/experimental/web/sql_injection_with_long_urls.yml +++ b/detections/experimental/web/sql_injection_with_long_urls.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Bhavin Patel, Splunk type: batch -datamodel: Web +datamodel: +- Web description: This search looks for long URLs that have several SQL commands visible within them. search: '| tstats `security_content_summariesonly` count from datamodel=Web where diff --git a/detections/experimental/web/supernova_webshell.yml b/detections/experimental/web/supernova_webshell.yml index 56c297d8f6..fc8f34a6dd 100644 --- a/detections/experimental/web/supernova_webshell.yml +++ b/detections/experimental/web/supernova_webshell.yml @@ -4,7 +4,8 @@ version: 1 date: '2021-01-06' author: John Stoner, Splunk type: batch -datamodel: Web +datamodel: +- Web description: This search aims to detect the Supernova webshell used in the SUNBURST attack. search: '| tstats `security_content_summariesonly` count from datamodel=Web.Web where diff --git a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml index 0ee6aac84b..324507d7ff 100644 --- a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml +++ b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml @@ -4,7 +4,8 @@ version: 3 date: '2021-01-14' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: Malicious actors often abuse legitimate Dynamic DNS services to host malicious payloads or interactive command and control nodes. Attackers will automate domain resolution changes by routing dynamic domains to countless IP addresses to diff --git a/detections/network/detect_ipv6_network_infrastructure_threats.yml b/detections/network/detect_ipv6_network_infrastructure_threats.yml index 785935f4fa..39240a442e 100644 --- a/detections/network/detect_ipv6_network_infrastructure_threats.yml +++ b/detections/network/detect_ipv6_network_infrastructure_threats.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-28' author: Mikael Bjerkeland, Splunk type: batch -datamodel: '' +datamodel: [] description: By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organization's network devices, we will be able to detect various attacks such as packet forging in the Infrastructure. diff --git a/detections/network/detect_large_outbound_icmp_packets.yml b/detections/network/detect_large_outbound_icmp_packets.yml index f1ce107730..5d1824035c 100644 --- a/detections/network/detect_large_outbound_icmp_packets.yml +++ b/detections/network/detect_large_outbound_icmp_packets.yml @@ -4,7 +4,8 @@ version: 2 date: '2018-06-01' author: Rico Valdez, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for outbound ICMP packets with a packet size larger than 1,000 bytes. Various threat actors have been known to use ICMP as a command and control channel for their attack infrastructure. Large ICMP packets from an diff --git a/detections/network/detect_outbound_smb_traffic.yml b/detections/network/detect_outbound_smb_traffic.yml index 06dd673e14..f501f5e6ab 100644 --- a/detections/network/detect_outbound_smb_traffic.yml +++ b/detections/network/detect_outbound_smb_traffic.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-21' author: Bhavin Patel, Stuart Hopkins from Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for outbound SMB connections made by hosts within your network to the Internet. SMB traffic is used for Windows file-sharing activity. One of the techniques often used by attackers involves retrieving the credential diff --git a/detections/network/detect_port_security_violation.yml b/detections/network/detect_port_security_violation.yml index 5d2cc4360a..7d38351e33 100644 --- a/detections/network/detect_port_security_violation.yml +++ b/detections/network/detect_port_security_violation.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-28' author: Mikael Bjerkeland, Splunk type: batch -datamodel: '' +datamodel: [] description: By enabling Port Security on a Cisco switch you can restrict input to an interface by limiting and identifying MAC addresses of the workstations that are allowed to access the port. When you assign secure MAC addresses to a secure diff --git a/detections/network/detect_rogue_dhcp_server.yml b/detections/network/detect_rogue_dhcp_server.yml index faca7f14f9..c3acdc47d9 100644 --- a/detections/network/detect_rogue_dhcp_server.yml +++ b/detections/network/detect_rogue_dhcp_server.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-08-11' author: Mikael Bjerkeland, Splunk type: batch -datamodel: '' +datamodel: [] description: By enabling DHCP Snooping as a Layer 2 Security measure on the organization's network devices, we will be able to detect unauthorized DHCP servers handing out DHCP leases to devices on the network (Man in the Middle attack). diff --git a/detections/network/detect_snicat_sni_exfiltration.yml b/detections/network/detect_snicat_sni_exfiltration.yml index 872addfb3b..862cb13a89 100644 --- a/detections/network/detect_snicat_sni_exfiltration.yml +++ b/detections/network/detect_snicat_sni_exfiltration.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-21' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for commands that the SNICat tool uses in the TLS SNI field. search: '`zeek_ssl` | rex field=server_name "(?(LIST|LS|SIZE|LD|CB|CD|EX|ALIVE|EXIT|WHERE|finito)-[A-Za-z0-9]{16}\.)" diff --git a/detections/network/detect_software_download_to_network_device.yml b/detections/network/detect_software_download_to_network_device.yml index 2795d49284..33db59428f 100644 --- a/detections/network/detect_software_download_to_network_device.yml +++ b/detections/network/detect_software_download_to_network_device.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-10-28' author: Mikael Bjerkeland, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled diff --git a/detections/network/detect_traffic_mirroring.yml b/detections/network/detect_traffic_mirroring.yml index ad5e1d565a..f270c9a423 100644 --- a/detections/network/detect_traffic_mirroring.yml +++ b/detections/network/detect_traffic_mirroring.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-10-28' author: Mikael Bjerkeland, Splunk type: batch -datamodel: '' +datamodel: [] description: Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised network infrastructure. Traffic mirroring is a native feature for some network devices and used for network analysis and may be configured diff --git a/detections/network/detect_unauthorized_assets_by_mac_address.yml b/detections/network/detect_unauthorized_assets_by_mac_address.yml index 7e8deb16ac..b71232d79f 100644 --- a/detections/network/detect_unauthorized_assets_by_mac_address.yml +++ b/detections/network/detect_unauthorized_assets_by_mac_address.yml @@ -4,7 +4,8 @@ version: 1 date: '2017-09-13' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Sessions +datamodel: +- Network_Sessions description: By populating the organization's assets within the assets_by_str.csv, we will be able to detect unauthorized devices that are trying to connect with the organization's network by inspecting DHCP request packets, which are issued by devices diff --git a/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml b/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml index 8e90004f05..0d9fa88013 100644 --- a/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml +++ b/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-07-28' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects SIGRed via Splunk Stream. search: '`stream_dns` | spath "query_type{}" | search "query_type{}" IN (SIG,KEY) | spath protocol_stack | search protocol_stack="ip:tcp:dns" | append [search `stream_tcp` diff --git a/detections/network/detect_windows_dns_sigred_via_zeek.yml b/detections/network/detect_windows_dns_sigred_via_zeek.yml index 46f7d0bc13..7a7e2410f9 100644 --- a/detections/network/detect_windows_dns_sigred_via_zeek.yml +++ b/detections/network/detect_windows_dns_sigred_via_zeek.yml @@ -4,7 +4,8 @@ version: 1 date: '2020-07-28' author: Shannon Davis, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search detects SIGRed via Zeek DNS and Zeek Conn data. search: '| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.query_type IN (SIG,KEY) by DNS.flow_id | rename DNS.flow_id as flow_id diff --git a/detections/network/detect_zerologon_via_zeek.yml b/detections/network/detect_zerologon_via_zeek.yml index a960699e2c..4a09aa0491 100644 --- a/detections/network/detect_zerologon_via_zeek.yml +++ b/detections/network/detect_zerologon_via_zeek.yml @@ -4,7 +4,7 @@ version: 1 date: '2020-09-15' author: Shannon Davis, Splunk type: batch -datamodel: '' +datamodel: [] description: This search detects attempts to run exploits for the Zerologon CVE-2020-1472 vulnerability via Zeek RPC search: '`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3) diff --git a/detections/network/dns_query_length_outliers___mltk.yml b/detections/network/dns_query_length_outliers___mltk.yml index b24c834649..ec6b240ebd 100644 --- a/detections/network/dns_query_length_outliers___mltk.yml +++ b/detections/network/dns_query_length_outliers___mltk.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-01-22' author: Rico Valdez, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search allows you to identify DNS requests that are unusually large for the record type being requested in your environment. search: '| tstats `security_content_summariesonly` count min(_time) as start_time diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index 0b23c44fb3..932d7bbc4c 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -4,7 +4,8 @@ version: 3 date: '2021-01-18' author: Bhavin Patel, Splunk type: batch -datamodel: Network_Resolution +datamodel: +- Network_Resolution description: This search allows you to identify DNS requests and compute the standard deviation on the length of the names being resolved, then filter on two times the standard deviation to show you those queries that are unusually large for your environment. diff --git a/detections/network/remote_desktop_network_bruteforce.yml b/detections/network/remote_desktop_network_bruteforce.yml index 88c8c819d7..b202102997 100644 --- a/detections/network/remote_desktop_network_bruteforce.yml +++ b/detections/network/remote_desktop_network_bruteforce.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-21' author: Jose Hernandez, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for RDP application network traffic and filters any source/destination pair generating more than twice the standard deviation of the average traffic. diff --git a/detections/network/remote_desktop_network_traffic.yml b/detections/network/remote_desktop_network_traffic.yml index e3afcb3232..4114cd1ea1 100644 --- a/detections/network/remote_desktop_network_traffic.yml +++ b/detections/network/remote_desktop_network_traffic.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-07' author: David Dorsey, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for network traffic on TCP/3389, the default port used by remote desktop. While remote desktop traffic is not uncommon on a network, it is usually associated with known hosts. This search will ignore common RDP sources diff --git a/detections/network/smb_traffic_spike.yml b/detections/network/smb_traffic_spike.yml index 5683922f41..313ae164cb 100644 --- a/detections/network/smb_traffic_spike.yml +++ b/detections/network/smb_traffic_spike.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-22' author: David Dorsey, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for spikes in the number of Server Message Block (SMB) traffic connections. search: '| tstats `security_content_summariesonly` count from datamodel=Network_Traffic diff --git a/detections/network/smb_traffic_spike___mltk.yml b/detections/network/smb_traffic_spike___mltk.yml index 94f891d77e..9121b5469f 100644 --- a/detections/network/smb_traffic_spike___mltk.yml +++ b/detections/network/smb_traffic_spike___mltk.yml @@ -4,7 +4,8 @@ version: 3 date: '2020-07-22' author: Rico Valdez, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the number of Server Message Block (SMB) connections. search: '| tstats `security_content_summariesonly` count values(All_Traffic.dest_ip) diff --git a/detections/network/tor_traffic.yml b/detections/network/tor_traffic.yml index 441dc1f906..cc8a33a88f 100644 --- a/detections/network/tor_traffic.yml +++ b/detections/network/tor_traffic.yml @@ -4,7 +4,8 @@ version: 2 date: '2020-07-22' author: David Dorsey, Splunk type: batch -datamodel: Network_Traffic +datamodel: +- Network_Traffic description: This search looks for network traffic identified as The Onion Router (TOR), a benign anonymity network which can be abused for a variety of nefarious purposes. diff --git a/detections/network/unusually_long_content_type_length.yml b/detections/network/unusually_long_content_type_length.yml index 11a0c2a5ca..a8cba96a7e 100644 --- a/detections/network/unusually_long_content_type_length.yml +++ b/detections/network/unusually_long_content_type_length.yml @@ -4,7 +4,7 @@ version: 1 date: '2017-10-13' author: Bhavin Patel, Splunk type: batch -datamodel: '' +datamodel: [] description: This search looks for unusually long strings in the Content-Type http header that the client sends the server. search: '`stream_http` | eval cs_content_type_length = len(cs_content_type) | where diff --git a/detections/web/web_fraud___account_harvesting.yml b/detections/web/web_fraud___account_harvesting.yml index d85ae0fe76..01cad47d36 100644 --- a/detections/web/web_fraud___account_harvesting.yml +++ b/detections/web/web_fraud___account_harvesting.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-08' author: Jim Apger, Splunk type: batch -datamodel: '' +datamodel: [] description: This search is used to identify the creation of multiple user accounts using the same email domain name. search: '`stream_http` http_content_type=text* uri="/magento2/customer/account/loginPost/" diff --git a/detections/web/web_fraud___anomalous_user_clickspeed.yml b/detections/web/web_fraud___anomalous_user_clickspeed.yml index 1a945257d5..9a82fac2eb 100644 --- a/detections/web/web_fraud___anomalous_user_clickspeed.yml +++ b/detections/web/web_fraud___anomalous_user_clickspeed.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-08' author: Jim Apger, Splunk type: batch -datamodel: '' +datamodel: [] description: This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect cadence (high periodicity or low standard deviation), resembling a script driven diff --git a/detections/web/web_fraud___password_sharing_across_accounts.yml b/detections/web/web_fraud___password_sharing_across_accounts.yml index 8ee30a4e83..e80e2f4b1f 100644 --- a/detections/web/web_fraud___password_sharing_across_accounts.yml +++ b/detections/web/web_fraud___password_sharing_across_accounts.yml @@ -4,7 +4,7 @@ version: 1 date: '2018-10-08' author: Jim Apger, Splunk type: batch -datamodel: '' +datamodel: [] description: This search is used to identify user accounts that share a common password. search: '`stream_http` http_content_type=text* uri=/magento2/customer/account/loginPost* | rex field=form_data "login\[username\]=(?[^&|^$]+)" | rex field=form_data