Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-03-31 01:42:50 -07:00
committed by GitHub
23 changed files with 85 additions and 148193 deletions
@@ -7,4 +7,4 @@ class JsonWriter():
def writeJsonObject(file_path : str, obj) -> None:
with open(file_path, 'w') as outfile:
json.dump(obj, outfile, ensure_ascii=False, indent=4)
json.dump(obj, outfile, ensure_ascii=False)
@@ -30,14 +30,14 @@ T1608.003,Install Digital Certificate,Resource Development,no
T1608.002,Upload Tool,Resource Development,Threat Group-3390
T1608.001,Upload Malware,Resource Development,TeamTNT|APT32
T1608,Stage Capabilities,Resource Development,no
T1016.001,Internet Connection Discovery,Discovery,APT29|UNC2452|Turla
T1016.001,Internet Connection Discovery,Discovery,APT29|Turla
T1553.005,Mark-of-the-Web Bypass,Defense Evasion,TA505
T1555.005,Password Managers,Credential Access,Fox Kitten|Operation Wocao
T1484.002,Domain Trust Modification,Defense Evasion|Privilege Escalation,APT29|UNC2452
T1484.002,Domain Trust Modification,Defense Evasion|Privilege Escalation,APT29
T1484.001,Group Policy Modification,Defense Evasion|Privilege Escalation,Indrik Spider
T1547.014,Active Setup,Persistence|Privilege Escalation,no
T1606.002,SAML Tokens,Credential Access,APT29|UNC2452
T1606.001,Web Cookies,Credential Access,APT29|UNC2452
T1606.002,SAML Tokens,Credential Access,APT29
T1606.001,Web Cookies,Credential Access,APT29
T1606,Forge Web Credentials,Credential Access,no
T1555.004,Windows Credential Manager,Credential Access,Stealth Falcon|OilRig|Turla
T1059.008,Network Device CLI,Execution,no
@@ -111,7 +111,7 @@ T1588,Obtain Capabilities,Resource Development,no
T1587.004,Exploits,Resource Development,no
T1587.003,Digital Certificates,Resource Development,APT29|PROMETHIUM
T1587.002,Code Signing Certificates,Resource Development,PROMETHIUM|Patchwork
T1587.001,Malware,Resource Development,TeamTNT|APT29|Lazarus Group|UNC2452|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver
T1587.001,Malware,Resource Development,TeamTNT|APT29|Lazarus Group|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver
T1587,Develop Capabilities,Resource Development,Kimsuky
T1586.002,Email Accounts,Resource Development,IndigoZebra|Leviathan|Magic Hound|Kimsuky
T1586.001,Social Media Accounts,Resource Development,Leviathan
@@ -124,14 +124,14 @@ T1584.005,Botnet,Resource Development,no
T1584.004,Server,Resource Development,Indrik Spider|Turla|APT16
T1584.003,Virtual Private Server,Resource Development,Turla
T1584.002,DNS Server,Resource Development,no
T1584.001,Domains,Resource Development,Transparent Tribe|Magic Hound|APT29|UNC2452|APT1
T1584.001,Domains,Resource Development,Transparent Tribe|Magic Hound|APT29|APT1
T1583.006,Web Services,Resource Development,IndigoZebra|ZIRCONIUM|MuddyWater|HAFNIUM|Lazarus Group|Turla|APT32|APT17|APT29
T1583.005,Botnet,Resource Development,no
T1583.004,Server,Resource Development,GALLIUM|Sandworm Team
T1583.003,Virtual Private Server,Resource Development,HAFNIUM|TEMP.Veles
T1583.002,DNS Server,Resource Development,no
T1584,Compromise Infrastructure,Resource Development,no
T1583.001,Domains,Resource Development,IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|UNC2452|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28
T1583.001,Domains,Resource Development,IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28
T1583,Acquire Infrastructure,Resource Development,no
T1564.007,VBA Stomping,Defense Evasion,no
T1558.004,AS-REP Roasting,Credential Access,no
@@ -162,10 +162,10 @@ T1546.015,Component Object Model Hijacking,Privilege Escalation|Persistence,APT2
T1071.004,DNS,Command And Control,Chimera|APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
T1071.003,Mail Protocols,Command And Control,Turla|Kimsuky|APT32|SilverTerrier|APT28
T1071.002,File Transfer Protocols,Command And Control,Kimsuky|APT41|SilverTerrier|Honeybee
T1071.001,Web Protocols,Command And Control,TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon
T1071.001,Web Protocols,Command And Control,TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon
T1572,Protocol Tunneling,Command And Control,Leviathan|CostaRicto|Chimera|Fox Kitten|OilRig|Cobalt Group|FIN6
T1048.003,Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol,Exfiltration,Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,APT28|APT29|UNC2452
T1048.002,Exfiltration Over Asymmetric Encrypted Non-C2 Protocol,Exfiltration,APT28|APT29
T1048.001,Exfiltration Over Symmetric Encrypted Non-C2 Protocol,Exfiltration,no
T1001.003,Protocol Impersonation,Command And Control,Higaisa|Lazarus Group
T1001.002,Steganography,Command And Control,APT29|Axiom
@@ -175,17 +175,17 @@ T1132.001,Standard Encoding,Command And Control,HAFNIUM|TA551|Sandworm Team|Trop
T1090.004,Domain Fronting,Command And Control,APT29
T1090.003,Multi-hop Proxy,Command And Control,Leviathan|CostaRicto|APT28|Operation Wocao|Inception|FIN4|APT29
T1090.002,External Proxy,Command And Control,Tonto Team|APT39|Silence|GALLIUM|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
T1090.001,Internal Proxy,Command And Control,APT29|Higaisa|UNC2452|Operation Wocao|APT39|Strider
T1090.001,Internal Proxy,Command And Control,APT29|Higaisa|Operation Wocao|APT39|Strider
T1102.003,One-Way Communication,Command And Control,Leviathan
T1102.002,Bidirectional Communication,Command And Control,ZIRCONIUM|MuddyWater|APT28|APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
T1102.001,Dead Drop Resolver,Command And Control,Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
T1571,Non-Standard Port,Command And Control,Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
T1074.002,Remote Data Staging,Collection,Leviathan|APT28|APT29|Chimera|UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
T1074.002,Remote Data Staging,Collection,Leviathan|APT28|APT29|Chimera|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
T1074.001,Local Data Staging,Collection,Indrik Spider|BackdoorDiplomacy|Mustang Panda|Sidewinder|Chimera|Kimsuky|APT39|Operation Wocao|GALLIUM|TEMP.Veles|Patchwork|Honeybee|Dragonfly 2.0|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28
T1078.004,Cloud Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,APT28|APT33
T1564.004,NTFS File Attributes,Defense Evasion,APT32
T1564.003,Hidden Window,Defense Evasion,Nomadic Octopus|Higaisa|Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32
T1078.003,Local Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|APT32
T1078.002,Domain Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,Naikon|Indrik Spider|Chimera|Operation Wocao|Sandworm Team|Wizard Spider|APT29|TA505|APT3|Threat Group-1314
T1078.001,Default Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,no
T1564.002,Hidden Users,Defense Evasion,Dragonfly 2.0
@@ -205,7 +205,7 @@ T1568.003,DNS Calculation,Command And Control,APT12
T1204.002,Malicious File,Execution,Nomadic Octopus|Indrik Spider|APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Tonto Team|Magic Hound|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|Kimsuky|FIN6|PROMETHIUM|APT30|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|FIN7|BRONZE BUTLER|Gorgon Group|OilRig|Dark Caracal|Cobalt Group|DarkHydrus|Rancor|Patchwork|APT32|APT19|MuddyWater|Lazarus Group|menuPass|APT37|Leviathan|TA459|APT29|APT28|FIN8|PLATINUM|Elderwood
T1204.001,Malicious Link,Execution,FIN7|Transparent Tribe|APT3|Magic Hound|APT28|APT29|Mustang Panda|Sidewinder|ZIRCONIUM|MuddyWater|Evilnum|Sandworm Team|Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|Turla|APT33
T1195.003,Compromise Hardware Supply Chain,Initial Access,no
T1195.002,Compromise Software Supply Chain,Initial Access,APT29|UNC2452|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
T1195.002,Compromise Software Supply Chain,Initial Access,APT29|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
T1195.001,Compromise Software Dependencies and Development Tools,Initial Access,no
T1568.001,Fast Flux DNS,Command And Control,menuPass|TA505
T1052.001,Exfiltration over USB,Exfiltration,Mustang Panda|Tropic Trooper
@@ -213,16 +213,16 @@ T1569.002,Service Execution,Execution,APT38|Chimera|Operation Wocao|Wizard Spide
T1569.001,Launchctl,Execution,no
T1569,System Services,Execution,no
T1568.002,Domain Generation Algorithms,Command And Control,TA551|APT41
T1568,Dynamic Resolution,Command And Control,Transparent Tribe|APT29|UNC2452
T1568,Dynamic Resolution,Command And Control,Transparent Tribe|APT29
T1011.001,Exfiltration Over Bluetooth,Exfiltration,no
T1567.002,Exfiltration to Cloud Storage,Exfiltration,FIN7|ZIRCONIUM|HAFNIUM|Chimera|Leviathan|Turla
T1567.001,Exfiltration to Code Repository,Exfiltration,no
T1059.006,Python,Execution,Tonto Team|APT37|ZIRCONIUM|MuddyWater|Turla|Operation Wocao|Kimsuky|APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
T1059.005,Visual Basic,Execution,OilRig|APT38|Transparent Tribe|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|APT39|Machete|Operation Wocao|Kimsuky|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
T1059.004,Unix Shell,Execution,TeamTNT|Rocke|APT41
T1059.003,Windows Command Shell,Execution,Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|UNC2452|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
T1059.003,Windows Command Shell,Execution,Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
T1059.002,AppleScript,Execution,no
T1059.001,PowerShell,Execution,Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|UNC2452|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
T1059.001,PowerShell,Execution,Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
T1567,Exfiltration Over Web Service,Exfiltration,APT28
T1497.003,Time Based Evasion,Defense Evasion|Discovery,no
T1497.002,User Activity Based Checks,Defense Evasion|Discovery,Darkhotel|FIN7
@@ -230,7 +230,7 @@ T1497.001,System Checks,Defense Evasion|Discovery,OilRig|Darkhotel|Evilnum|Frank
T1498.002,Reflection Amplification,Impact,no
T1498.001,Direct Network Flood,Impact,no
T1566.003,Spearphishing via Service,Initial Access,APT29|Ajax Security Team|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
T1566.002,Spearphishing Link,Initial Access,Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound
T1566.002,Spearphishing Link,Initial Access,Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound
T1566.001,Spearphishing Attachment,Initial Access,APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Nomadic Octopus|Tonto Team|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|APT1|FIN6|APT30|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|DarkHydrus|Lazarus Group|Gorgon Group|OilRig|BRONZE BUTLER|APT19|APT32|Cobalt Group|Rancor|FIN7|Dragonfly 2.0|MuddyWater|APT28|TA459|APT29|APT37|Leviathan|FIN8|Patchwork|menuPass|Elderwood|PLATINUM
T1566,Phishing,Initial Access,GOLD SOUTHFIELD|Dragonfly
T1565.003,Runtime Data Manipulation,Impact,APT38
@@ -250,10 +250,10 @@ T1087.003,Email Account,Discovery,Sandworm Team|TA505
T1087.002,Domain Account,Discovery,MuddyWater|Fox Kitten|Operation Wocao|Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
T1087.001,Local Account,Discovery,Chimera|Fox Kitten|Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
T1553.004,Install Root Certificate,Defense Evasion,no
T1562.004,Disable or Modify System Firewall,Defense Evasion,TeamTNT|APT38|APT29|UNC2452|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
T1562.004,Disable or Modify System Firewall,Defense Evasion,TeamTNT|APT38|APT29|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
T1562.003,Impair Command History Logging,Defense Evasion,APT38
T1562.002,Disable Windows Event Logging,Defense Evasion,Sandworm Team|APT29|UNC2452|Threat Group-3390
T1562.001,Disable or Modify Tools,Defense Evasion,TeamTNT|Indrik Spider|APT29|MuddyWater|UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
T1562.002,Disable Windows Event Logging,Defense Evasion,Sandworm Team|APT29|Threat Group-3390
T1562.001,Disable or Modify Tools,Defense Evasion,TeamTNT|Indrik Spider|APT29|MuddyWater|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
T1562,Impair Defenses,Defense Evasion,no
T1003.004,LSA Secrets,Credential Access,OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
T1003.005,Cached Domain Credentials,Credential Access,OilRig|MuddyWater|Leafminer|APT33
@@ -262,7 +262,7 @@ T1561.001,Disk Content Wipe,Impact,Lazarus Group
T1561,Disk Wipe,Impact,no
T1560.003,Archive via Custom Method,Collection,Mustang Panda|Lazarus Group|Kimsuky|CopyKittens|FIN6
T1560.002,Archive via Library,Collection,Lazarus Group|Threat Group-3390
T1560.001,Archive via Utility,Collection,APT28|APT29|Mustang Panda|HAFNIUM|UNC2452|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
T1560.001,Archive via Utility,Collection,APT28|APT29|Mustang Panda|HAFNIUM|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
T1560,Archive Collected Data,Collection,Leviathan|menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
T1499.004,Application or System Exploitation,Impact,no
T1499.003,Application Exhaustion Flood,Impact,no
@@ -271,7 +271,7 @@ T1499.001,OS Exhaustion Flood,Impact,no
T1491.002,External Defacement,Impact,Sandworm Team
T1491.001,Internal Defacement,Impact,Lazarus Group
T1114.003,Email Forwarding Rule,Collection,Silent Librarian|Kimsuky
T1114.002,Remote Email Collection,Collection,APT29|HAFNIUM|Chimera|UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
T1114.002,Remote Email Collection,Collection,APT29|HAFNIUM|Chimera|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
T1114.001,Local Email Collection,Collection,Chimera|Magic Hound|APT1
T1134.005,SID-History Injection,Defense Evasion|Privilege Escalation,no
T1134.004,Parent PID Spoofing,Defense Evasion|Privilege Escalation,no
@@ -280,7 +280,7 @@ T1134.002,Create Process with Token,Defense Evasion|Privilege Escalation,Turla|L
T1134.001,Token Impersonation/Theft,Defense Evasion|Privilege Escalation,FIN8|APT28
T1213.002,Sharepoint,Collection,Chimera|Ke3chang|APT28
T1213.001,Confluence,Collection,no
T1555.003,Credentials from Web Browsers,Credential Access,Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats
T1555.003,Credentials from Web Browsers,Credential Access,Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|MuddyWater|APT37|Patchwork|Molerats
T1555.002,Securityd Memory,Credential Access,no
T1555.001,Keychain,Credential Access,no
T1559.002,Dynamic Data Exchange,Execution,Leviathan|Sidewinder|Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|FIN7|APT28
@@ -297,36 +297,36 @@ T1556,Modify Authentication Process,Credential Access|Defense Evasion|Persistenc
T1056.004,Credential API Hooking,Collection|Credential Access,PLATINUM
T1056.003,Web Portal Capture,Collection|Credential Access,no
T1056.002,GUI Input Capture,Collection|Credential Access,FIN4
T1056.001,Keylogging,Collection|Credential Access,Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
T1555,Credentials from Password Stores,Credential Access,APT29|Evilnum|UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon
T1056.001,Keylogging,Collection|Credential Access,Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
T1555,Credentials from Password Stores,Credential Access,APT29|Evilnum|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon
T1552.005,Cloud Instance Metadata API,Credential Access,TeamTNT
T1003.008,/etc/passwd and /etc/shadow,Credential Access,no
T1003.007,Proc Filesystem,Credential Access,no
T1003.006,DCSync,Credential Access,APT29|UNC2452|Operation Wocao
T1558.003,Kerberoasting,Credential Access,FIN7|APT29|UNC2452|Operation Wocao|Wizard Spider
T1003.006,DCSync,Credential Access,APT29|Operation Wocao
T1558.003,Kerberoasting,Credential Access,FIN7|APT29|Operation Wocao|Wizard Spider
T1552.006,Group Policy Preferences,Credential Access,APT33
T1003.003,NTDS,Credential Access,APT28|Mustang Panda|HAFNIUM|Fox Kitten|menuPass|Wizard Spider|Chimera|FIN6|Dragonfly 2.0
T1003.002,Security Account Manager,Credential Access,Wizard Spider|Threat Group-3390|Ke3chang|GALLIUM|Night Dragon|Dragonfly 2.0|menuPass
T1003.001,LSASS Memory,Credential Access,Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
T1003.001,LSASS Memory,Credential Access,Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
T1110.004,Credential Stuffing,Credential Access,Chimera
T1110.003,Password Spraying,Credential Access,Sandworm Team|APT29|Silent Librarian|Chimera|APT28|APT33|Leafminer|Lazarus Group
T1110.002,Password Cracking,Credential Access,FIN6|APT41|Dragonfly 2.0|APT3
T1110.001,Password Guessing,Credential Access,APT28
T1021.006,Windows Remote Management,Lateral Movement,APT29|UNC2452|Chimera|Wizard Spider|Threat Group-3390
T1021.006,Windows Remote Management,Lateral Movement,APT29|Chimera|Wizard Spider|Threat Group-3390
T1021.005,VNC,Lateral Movement,FIN7|Fox Kitten|GCMAN
T1021.004,SSH,Lateral Movement,TeamTNT|FIN7|Fox Kitten|Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
T1021.003,Distributed Component Object Model,Lateral Movement,no
T1021.002,SMB/Windows Admin Shares,Lateral Movement,Sandworm Team|APT28|Fox Kitten|APT41|Operation Wocao|Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
T1021.001,Remote Desktop Protocol,Lateral Movement,Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
T1021.001,Remote Desktop Protocol,Lateral Movement,Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
T1554,Compromise Client Software Binary,Persistence,no
T1036.006,Space after Filename,Defense Evasion,no
T1036.005,Match Legitimate Name or Location,Defense Evasion,APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|UNC2452|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
T1036.004,Masquerade Task or Service,Defense Evasion,BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|UNC2452|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
T1036.005,Match Legitimate Name or Location,Defense Evasion,APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
T1036.004,Masquerade Task or Service,Defense Evasion,BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
T1036.003,Rename System Utilities,Defense Evasion,menuPass|APT32|GALLIUM
T1036.002,Right-to-Left Override,Defense Evasion,Ferocious Kitten|BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
T1036.001,Invalid Code Signature,Defense Evasion,Windshift|APT37
T1553.003,SIP and Trust Provider Hijacking,Defense Evasion,no
T1553.002,Code Signing,Defense Evasion,menuPass|APT29|GALLIUM|UNC2452|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
T1553.002,Code Signing,Defense Evasion,menuPass|APT29|GALLIUM|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
T1553.001,Gatekeeper Bypass,Defense Evasion,no
T1553,Subvert Trust Controls,Defense Evasion,no
T1027.003,Steganography,Defense Evasion,Andariel|Leviathan|TA551|BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
@@ -334,21 +334,21 @@ T1027.002,Software Packing,Defense Evasion,Sandworm Team|Kimsuky|TeamTNT|ZIRCONI
T1027.001,Binary Padding,Defense Evasion,APT29|Mustang Panda|Higaisa|Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
T1222.002,Linux and Mac File and Directory Permissions Modification,Defense Evasion,TeamTNT|Rocke|APT32
T1222.001,Windows File and Directory Permissions Modification,Defense Evasion,Wizard Spider
T1552.004,Private Keys,Credential Access,TeamTNT|APT29|UNC2452|Operation Wocao|Rocke
T1552.004,Private Keys,Credential Access,TeamTNT|APT29|Operation Wocao|Rocke
T1552.003,Bash History,Credential Access,no
T1552.002,Credentials in Registry,Credential Access,APT32
T1552.001,Credentials In Files,Credential Access,TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3
T1552.001,Credentials In Files,Credential Access,TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|MuddyWater|APT3
T1552,Unsecured Credentials,Credential Access,no
T1216.001,PubPrn,Defense Evasion,APT32
T1070.006,Timestomp,Defense Evasion,APT38|APT29|UNC2452|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
T1070.006,Timestomp,Defense Evasion,APT38|APT29|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
T1070.005,Network Share Connection Removal,Defense Evasion,Threat Group-3390
T1070.004,File Deletion,Defense Evasion,TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|UNC2452|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29
T1070.004,File Deletion,Defense Evasion,TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29
T1070.003,Clear Command History,Defense Evasion,TeamTNT|menuPass|APT41
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,APT29|UNC2452
T1550.004,Web Session Cookie,Defense Evasion|Lateral Movement,APT29
T1550.001,Application Access Token,Defense Evasion|Lateral Movement,APT28
T1550.003,Pass the Ticket,Defense Evasion|Lateral Movement,APT32|BRONZE BUTLER|APT29
T1550.002,Pass the Hash,Defense Evasion|Lateral Movement,Chimera|Kimsuky|GALLIUM|APT32|Night Dragon|APT28|APT1
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,APT29|UNC2452
T1550,Use Alternate Authentication Material,Defense Evasion|Lateral Movement,APT29
T1548.004,Elevated Execution with Prompt,Privilege Escalation|Defense Evasion,no
T1548.003,Sudo and Sudo Caching,Privilege Escalation|Defense Evasion,no
T1548.002,Bypass User Account Control,Privilege Escalation|Defense Evasion,Evilnum|APT37|MuddyWater|Threat Group-3390|Honeybee|Cobalt Group|BRONZE BUTLER|Patchwork|APT29
@@ -382,7 +382,7 @@ T1546.007,Netsh Helper DLL,Privilege Escalation|Persistence,no
T1546.006,LC_LOAD_DYLIB Addition,Privilege Escalation|Persistence,no
T1546.005,Trap,Privilege Escalation|Persistence,no
T1546.004,Unix Shell Configuration Modification,Privilege Escalation|Persistence,no
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,FIN8|Mustang Panda|UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29
T1546.003,Windows Management Instrumentation Event Subscription,Privilege Escalation|Persistence,FIN8|Mustang Panda|APT33|Blue Mockingbird|Turla|Leviathan|APT29
T1546.002,Screensaver,Privilege Escalation|Persistence,no
T1546.001,Change Default File Association,Privilege Escalation|Persistence,Kimsuky
T1547.001,Registry Run Keys / Startup Folder,Persistence|Privilege Escalation,TeamTNT|Naikon|Windshift|Mustang Panda|ZIRCONIUM|Higaisa|Sidewinder|APT28|Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Kimsuky|APT33|APT39|APT32|APT18|Dark Caracal|Threat Group-3390|Honeybee|Turla|Cobalt Group|Ke3chang|Dragonfly 2.0|APT19|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|APT3|Magic Hound|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
@@ -393,12 +393,12 @@ T1218.005,Mshta,Defense Evasion,Mustang Panda|TA551|Sidewinder|Inception|Kimsuky
T1218.004,InstallUtil,Defense Evasion,Mustang Panda|menuPass
T1218.001,Compiled HTML File,Defense Evasion,APT41|Silence|Dark Caracal|OilRig|Lazarus Group
T1218.003,CMSTP,Defense Evasion,Cobalt Group|MuddyWater
T1218.011,Rundll32,Defense Evasion,APT38|HAFNIUM|TA551|UNC2452|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
T1218.011,Rundll32,Defense Evasion,APT38|HAFNIUM|TA551|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
T1547,Boot or Logon Autostart Execution,Persistence|Privilege Escalation,no
T1546,Event Triggered Execution,Privilege Escalation|Persistence,no
T1098.003,Add Office 365 Global Administrator Role,Persistence,no
T1098.002,Exchange Email Delegate Permissions,Persistence,APT28|APT29|UNC2452|Magic Hound
T1098.001,Additional Cloud Credentials,Persistence,APT29|UNC2452
T1098.002,Exchange Email Delegate Permissions,Persistence,APT28|APT29|Magic Hound
T1098.001,Additional Cloud Credentials,Persistence,APT29
T1543.004,Launch Daemon,Persistence|Privilege Escalation,no
T1543.003,Windows Service,Persistence|Privilege Escalation,TeamTNT|APT38|PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|FIN7|APT19|Threat Group-3390|Honeybee|APT3|Lazarus Group|Carbanak
T1543.002,Systemd Service,Persistence|Privilege Escalation,TeamTNT|Rocke
@@ -427,9 +427,8 @@ T1505.003,Web Shell,Persistence,BackdoorDiplomacy|APT38|APT29|APT28|Tonto Team|S
T1505.002,Transport Agent,Persistence,no
T1505.001,SQL Stored Procedures,Persistence,Sandworm Team
T1053.003,Cron,Execution|Persistence|Privilege Escalation,APT38|Rocke
T1053.004,Launchd,Execution|Persistence|Privilege Escalation,no
T1053.001,At (Linux),Execution|Persistence|Privilege Escalation,no
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|UNC2452|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29
T1053.005,Scheduled Task,Execution|Persistence|Privilege Escalation,APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29
T1053.002,At (Windows),Execution|Persistence|Privilege Escalation,BRONZE BUTLER|Threat Group-3390|APT18
T1542,Pre-OS Boot,Defense Evasion|Persistence,no
T1137.001,Office Template Macros,Persistence,MuddyWater
@@ -464,7 +463,7 @@ T1489,Service Stop,Impact,Indrik Spider|Wizard Spider|Lazarus Group
T1486,Data Encrypted for Impact,Impact,FIN7|Indrik Spider|APT41|TA505|APT38
T1485,Data Destruction,Impact,Sandworm Team|Lazarus Group|APT38
T1484,Domain Policy Modification,Defense Evasion|Privilege Escalation,no
T1482,Domain Trust Discovery,Discovery,FIN8|APT29|Chimera|UNC2452
T1482,Domain Trust Discovery,Discovery,FIN8|APT29|Chimera
T1480,Execution Guardrails,Defense Evasion,no
T1221,Template Injection,Defense Evasion,Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|DarkHydrus|Dragonfly 2.0
T1222,File and Directory Permissions Modification,Defense Evasion,no
@@ -481,7 +480,7 @@ T1199,Trusted Relationship,Initial Access,APT29|Sandworm Team|GOLD SOUTHFIELD|AP
T1218,Signed Binary Proxy Execution,Defense Evasion,no
T1204,User Execution,Execution,no
T1213,Data from Information Repositories,Collection,APT28|Fox Kitten|FIN6|Turla
T1190,Exploit Public-Facing Application,Initial Access,BackdoorDiplomacy|menuPass|Volatile Cedar|UNC2452|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom
T1190,Exploit Public-Facing Application,Initial Access,BackdoorDiplomacy|menuPass|Volatile Cedar|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom
T1210,Exploitation of Remote Services,Lateral Movement,Tonto Team|FIN7|Fox Kitten|menuPass|Wizard Spider|Threat Group-3390|APT28
T1200,Hardware Additions,Initial Access,DarkVishnya
T1202,Indirect Command Execution,Defense Evasion,no
@@ -489,18 +488,15 @@ T1219,Remote Access Software,Command And Control,TeamTNT|Mustang Panda|MuddyWate
T1207,Rogue Domain Controller,Defense Evasion,no
T1216,Signed Script Proxy Execution,Defense Evasion,no
T1205,Traffic Signaling,Defense Evasion|Persistence|Command And Control,no
T1176,Browser Extensions,Persistence,Kimsuky|Stolen Pencil
T1176,Browser Extensions,Persistence,Kimsuky
T1187,Forced Authentication,Credential Access,DarkHydrus|Dragonfly 2.0
T1175,Component Object Model and Distributed COM,Lateral Movement|Execution,no
T1185,Browser Session Hijacking,Collection,no
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,APT39|APT29|ZIRCONIUM|Higaisa|UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
T1140,Deobfuscate/Decode Files or Information,Defense Evasion,APT39|APT29|ZIRCONIUM|Higaisa|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
T1134,Access Token Manipulation,Defense Evasion|Privilege Escalation,FIN6|Blue Mockingbird
T1149,LC_MAIN Hijacking,Defense Evasion,no
T1136,Create Account,Persistence,Sandworm Team|Indrik Spider
T1135,Network Share Discovery,Discovery,Tonto Team|APT38|Chimera|Operation Wocao|Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
T1137,Office Application Startup,Persistence,Gamaredon Group|APT32
T1153,Source,Execution,no
T1133,External Remote Services,Persistence|Initial Access,TeamTNT|Leviathan|APT28|APT29|UNC2452|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
T1133,External Remote Services,Persistence|Initial Access,TeamTNT|Leviathan|APT28|APT29|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
T1132,Data Encoding,Command And Control,no
T1129,Shared Modules,Execution,no
T1127,Trusted Developer Utilities Proxy Execution,Defense Evasion,no
@@ -515,9 +511,8 @@ T1113,Screen Capture,Collection,GOLD SOUTHFIELD|Gamaredon Group|APT39|Silence|Mu
T1112,Modify Registry,Defense Evasion,Operation Wocao|Kimsuky|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Patchwork|Gorgon Group|Threat Group-3390|Dragonfly 2.0|APT19|Honeybee|FIN8
T1111,Two-Factor Authentication Interception,Credential Access,Chimera|Operation Wocao
T1110,Brute Force,Credential Access,APT38|APT28|Fox Kitten|DarkVishnya|APT39|OilRig|FIN5|Turla
T1108,Redundant Access,Defense Evasion|Persistence,no
T1106,Native API,Execution,APT38|Higaisa|menuPass|Operation Wocao|Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group
T1105,Ingress Tool Transfer,Command And Control,TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|UNC2452|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
T1105,Ingress Tool Transfer,Command And Control,TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
T1104,Multi-Stage Channels,Command And Control,APT41|MuddyWater|APT3
T1102,Web Service,Command And Control,TeamTNT|FIN8|Fox Kitten|Turla|APT32|Gamaredon Group|Rocke|Inception|FIN6
T1098,Account Manipulation,Persistence,Sandworm Team|APT3|Dragonfly 2.0|Lazarus Group
@@ -525,47 +520,40 @@ T1095,Non-Application Layer Protocol,Command And Control,BackdoorDiplomacy|HAFNI
T1092,Communication Through Removable Media,Command And Control,APT28
T1091,Replication Through Removable Media,Lateral Movement|Initial Access,Mustang Panda|Tropic Trooper|Darkhotel|APT28
T1090,Proxy,Command And Control,Windigo|Fox Kitten|Operation Wocao|Sandworm Team|Blue Mockingbird|APT41|Turla
T1087,Account Discovery,Discovery,APT29|UNC2452
T1083,File and Directory Discovery,Discovery,APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|UNC2452|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
T1082,System Information Discovery,Discovery,TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|UNC2452|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
T1087,Account Discovery,Discovery,APT29
T1083,File and Directory Discovery,Discovery,APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
T1082,System Information Discovery,Discovery,TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
T1080,Taint Shared Content,Lateral Movement,Gamaredon Group|BRONZE BUTLER|Darkhotel
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,FIN7|Leviathan|APT29|Silent Librarian|UNC2452|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
T1078,Valid Accounts,Defense Evasion|Persistence|Privilege Escalation|Initial Access,FIN7|Leviathan|APT29|Silent Librarian|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
T1074,Data Staged,Collection,Wizard Spider
T1072,Software Deployment Tools,Execution|Lateral Movement,Silence|APT32|Threat Group-1314
T1071,Application Layer Protocol,Command And Control,TeamTNT|Rocke|Magic Hound|Dragonfly 2.0
T1070,Indicator Removal on Host,Defense Evasion,APT29|UNC2452
T1069,Permission Groups Discovery,Discovery,APT29|UNC2452|TA505|APT3
T1070,Indicator Removal on Host,Defense Evasion,APT29
T1069,Permission Groups Discovery,Discovery,APT29|TA505|APT3
T1068,Exploitation for Privilege Escalation,Privilege Escalation,Tonto Team|ZIRCONIUM|Turla|Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
T1064,Scripting,Defense Evasion|Execution,no
T1062,Hypervisor,Persistence,no
T1061,Graphical User Interface,Execution,no
T1059,Command and Scripting Interpreter,Execution,APT37|Windigo|Fox Kitten|APT32|Whitefly|APT39|Dragonfly 2.0|FIN7|APT19|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
T1057,Process Discovery,Discovery,TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|UNC2452|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
T1057,Process Discovery,Discovery,TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
T1056,Input Capture,Collection|Credential Access,APT39
T1055,Process Injection,Defense Evasion|Privilege Escalation,Operation Wocao|APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|Turla|APT37|Honeybee|PLATINUM
T1053,Scheduled Task/Job,Execution|Persistence|Privilege Escalation,no
T1052,Exfiltration Over Physical Medium,Exfiltration,no
T1051,Shared Webroot,Lateral Movement,no
T1049,System Network Connections Discovery,Discovery,TeamTNT|Andariel|BackdoorDiplomacy|Mustang Panda|MuddyWater|Chimera|Sandworm Team|Operation Wocao|Tropic Trooper|APT41|APT38|GALLIUM|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
T1048,Exfiltration Over Alternative Protocol,Exfiltration,no
T1047,Windows Management Instrumentation,Execution,Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|UNC2452|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
T1047,Windows Management Instrumentation,Execution,Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
T1046,Network Service Scanning,Discovery,TeamTNT|BackdoorDiplomacy|Naikon|CostaRicto|Chimera|Fox Kitten|Operation Wocao|Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|OilRig|Cobalt Group|Leafminer|menuPass|Suckfly|FIN6|Threat Group-3390
T1043,Commonly Used Port,Command And Control,OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|APT19|Dragonfly 2.0|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390
T1041,Exfiltration Over C2 Channel,Exfiltration,Leviathan|ZIRCONIUM|Higaisa|Chimera|APT39|Operation Wocao|Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|GALLIUM|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
T1040,Network Sniffing,Credential Access|Discovery,Kimsuky|Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28
T1040,Network Sniffing,Credential Access|Discovery,Kimsuky|Sandworm Team|DarkVishnya|APT33|APT28
T1039,Data from Network Shared Drive,Collection,APT28|Chimera|Fox Kitten|Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass
T1037,Boot or Logon Initialization Scripts,Persistence|Privilege Escalation,Rocke
T1036,Masquerading,Defense Evasion,APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0
T1034,Path Interception,Persistence|Privilege Escalation,no
T1036,Masquerading,Defense Evasion,APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0
T1033,System Owner/User Discovery,Discovery,APT38|Windshift|ZIRCONIUM|Sidewinder|Chimera|Sandworm Team|Operation Wocao|Wizard Spider|Frankenstein|APT41|GALLIUM|Tropic Trooper|APT39|MuddyWater|APT37|Dragonfly 2.0|APT19|APT32|Magic Hound|OilRig|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
T1030,Data Transfer Size Limits,Exfiltration,APT28|Threat Group-3390
T1029,Scheduled Transfer,Exfiltration,Higaisa
T1027,Obfuscated Files or Information,Defense Evasion,TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|UNC2452|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
T1026,Multiband Communication,Command And Control,Lazarus Group
T1027,Obfuscated Files or Information,Defense Evasion,TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
T1025,Data from Removable Media,Collection,Turla|Gamaredon Group|APT28
T1021,Remote Services,Lateral Movement,no
T1020,Automated Exfiltration,Exfiltration,Sidewinder|Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee
T1018,Remote System Discovery,Discovery,Indrik Spider|Naikon|APT29|UNC2452|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
T1018,Remote System Discovery,Discovery,Indrik Spider|Naikon|APT29|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
T1016,System Network Configuration Discovery,Discovery,TeamTNT|ZIRCONIUM|Mustang Panda|Higaisa|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|GALLIUM|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|Threat Group-3390|menuPass|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
T1014,Rootkit,Defense Evasion,TeamTNT|Rocke|APT41|APT28|Winnti Group
T1012,Query Registry,Discovery,ZIRCONIUM|Chimera|Fox Kitten|APT39|Operation Wocao|APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
@@ -574,6 +562,6 @@ T1010,Application Window Discovery,Discovery,Lazarus Group
T1008,Fallback Channels,Command And Control,FIN7|APT41|OilRig|Lazarus Group
T1007,System Service Discovery,Discovery,Indrik Spider|Chimera|Operation Wocao|BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
T1006,Direct Volume Access,Defense Evasion,no
T1005,Data from Local System,Collection,FIN7|APT41|APT38|Andariel|APT29|Windigo|UNC2452|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
T1005,Data from Local System,Collection,FIN7|APT41|APT38|Andariel|APT29|Windigo|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
T1003,OS Credential Dumping,Credential Access,Tonto Team|APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
T1001,Data Obfuscation,Command And Control,Operation Wocao|Axiom
1 mitre_id technique tactics groups
30 T1608.002 Upload Tool Resource Development Threat Group-3390
31 T1608.001 Upload Malware Resource Development TeamTNT|APT32
32 T1608 Stage Capabilities Resource Development no
33 T1016.001 Internet Connection Discovery Discovery APT29|UNC2452|Turla APT29|Turla
34 T1553.005 Mark-of-the-Web Bypass Defense Evasion TA505
35 T1555.005 Password Managers Credential Access Fox Kitten|Operation Wocao
36 T1484.002 Domain Trust Modification Defense Evasion|Privilege Escalation APT29|UNC2452 APT29
37 T1484.001 Group Policy Modification Defense Evasion|Privilege Escalation Indrik Spider
38 T1547.014 Active Setup Persistence|Privilege Escalation no
39 T1606.002 SAML Tokens Credential Access APT29|UNC2452 APT29
40 T1606.001 Web Cookies Credential Access APT29|UNC2452 APT29
41 T1606 Forge Web Credentials Credential Access no
42 T1555.004 Windows Credential Manager Credential Access Stealth Falcon|OilRig|Turla
43 T1059.008 Network Device CLI Execution no
111 T1587.004 Exploits Resource Development no
112 T1587.003 Digital Certificates Resource Development APT29|PROMETHIUM
113 T1587.002 Code Signing Certificates Resource Development PROMETHIUM|Patchwork
114 T1587.001 Malware Resource Development TeamTNT|APT29|Lazarus Group|UNC2452|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver TeamTNT|APT29|Lazarus Group|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver
115 T1587 Develop Capabilities Resource Development Kimsuky
116 T1586.002 Email Accounts Resource Development IndigoZebra|Leviathan|Magic Hound|Kimsuky
117 T1586.001 Social Media Accounts Resource Development Leviathan
124 T1584.004 Server Resource Development Indrik Spider|Turla|APT16
125 T1584.003 Virtual Private Server Resource Development Turla
126 T1584.002 DNS Server Resource Development no
127 T1584.001 Domains Resource Development Transparent Tribe|Magic Hound|APT29|UNC2452|APT1 Transparent Tribe|Magic Hound|APT29|APT1
128 T1583.006 Web Services Resource Development IndigoZebra|ZIRCONIUM|MuddyWater|HAFNIUM|Lazarus Group|Turla|APT32|APT17|APT29
129 T1583.005 Botnet Resource Development no
130 T1583.004 Server Resource Development GALLIUM|Sandworm Team
131 T1583.003 Virtual Private Server Resource Development HAFNIUM|TEMP.Veles
132 T1583.002 DNS Server Resource Development no
133 T1584 Compromise Infrastructure Resource Development no
134 T1583.001 Domains Resource Development IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|UNC2452|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28 IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28
135 T1583 Acquire Infrastructure Resource Development no
136 T1564.007 VBA Stomping Defense Evasion no
137 T1558.004 AS-REP Roasting Credential Access no
162 T1071.004 DNS Command And Control Chimera|APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7
163 T1071.003 Mail Protocols Command And Control Turla|Kimsuky|APT32|SilverTerrier|APT28
164 T1071.002 File Transfer Protocols Command And Control Kimsuky|APT41|SilverTerrier|Honeybee
165 T1071.001 Web Protocols Command And Control TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|UNC2452|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon
166 T1572 Protocol Tunneling Command And Control Leviathan|CostaRicto|Chimera|Fox Kitten|OilRig|Cobalt Group|FIN6
167 T1048.003 Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Exfiltration Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group
168 T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration APT28|APT29|UNC2452 APT28|APT29
169 T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol Exfiltration no
170 T1001.003 Protocol Impersonation Command And Control Higaisa|Lazarus Group
171 T1001.002 Steganography Command And Control APT29|Axiom
175 T1090.004 Domain Fronting Command And Control APT29
176 T1090.003 Multi-hop Proxy Command And Control Leviathan|CostaRicto|APT28|Operation Wocao|Inception|FIN4|APT29
177 T1090.002 External Proxy Command And Control Tonto Team|APT39|Silence|GALLIUM|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28
178 T1090.001 Internal Proxy Command And Control APT29|Higaisa|UNC2452|Operation Wocao|APT39|Strider APT29|Higaisa|Operation Wocao|APT39|Strider
179 T1102.003 One-Way Communication Command And Control Leviathan
180 T1102.002 Bidirectional Communication Command And Control ZIRCONIUM|MuddyWater|APT28|APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak
181 T1102.001 Dead Drop Resolver Command And Control Rocke|APT41|BRONZE BUTLER|RTM|Patchwork
182 T1571 Non-Standard Port Command And Control Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7
183 T1074.002 Remote Data Staging Collection Leviathan|APT28|APT29|Chimera|UNC2452|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8 Leviathan|APT28|APT29|Chimera|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8
184 T1074.001 Local Data Staging Collection Indrik Spider|BackdoorDiplomacy|Mustang Panda|Sidewinder|Chimera|Kimsuky|APT39|Operation Wocao|GALLIUM|TEMP.Veles|Patchwork|Honeybee|Dragonfly 2.0|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28
185 T1078.004 Cloud Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access APT28|APT33
186 T1564.004 NTFS File Attributes Defense Evasion APT32
187 T1564.003 Hidden Window Defense Evasion Nomadic Octopus|Higaisa|Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound
188 T1078.003 Local Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|Stolen Pencil|APT32 Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|APT32
189 T1078.002 Domain Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access Naikon|Indrik Spider|Chimera|Operation Wocao|Sandworm Team|Wizard Spider|APT29|TA505|APT3|Threat Group-1314
190 T1078.001 Default Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access no
191 T1564.002 Hidden Users Defense Evasion Dragonfly 2.0
205 T1204.002 Malicious File Execution Nomadic Octopus|Indrik Spider|APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Tonto Team|Magic Hound|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|Kimsuky|FIN6|PROMETHIUM|APT30|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|FIN7|BRONZE BUTLER|Gorgon Group|OilRig|Dark Caracal|Cobalt Group|DarkHydrus|Rancor|Patchwork|APT32|APT19|MuddyWater|Lazarus Group|menuPass|APT37|Leviathan|TA459|APT29|APT28|FIN8|PLATINUM|Elderwood
206 T1204.001 Malicious Link Execution FIN7|Transparent Tribe|APT3|Magic Hound|APT28|APT29|Mustang Panda|Sidewinder|ZIRCONIUM|MuddyWater|Evilnum|Sandworm Team|Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|Turla|APT33
207 T1195.003 Compromise Hardware Supply Chain Initial Access no
208 T1195.002 Compromise Software Supply Chain Initial Access APT29|UNC2452|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41 APT29|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41
209 T1195.001 Compromise Software Dependencies and Development Tools Initial Access no
210 T1568.001 Fast Flux DNS Command And Control menuPass|TA505
211 T1052.001 Exfiltration over USB Exfiltration Mustang Panda|Tropic Trooper
213 T1569.001 Launchctl Execution no
214 T1569 System Services Execution no
215 T1568.002 Domain Generation Algorithms Command And Control TA551|APT41
216 T1568 Dynamic Resolution Command And Control Transparent Tribe|APT29|UNC2452 Transparent Tribe|APT29
217 T1011.001 Exfiltration Over Bluetooth Exfiltration no
218 T1567.002 Exfiltration to Cloud Storage Exfiltration FIN7|ZIRCONIUM|HAFNIUM|Chimera|Leviathan|Turla
219 T1567.001 Exfiltration to Code Repository Exfiltration no
220 T1059.006 Python Execution Tonto Team|APT37|ZIRCONIUM|MuddyWater|Turla|Operation Wocao|Kimsuky|APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete
221 T1059.005 Visual Basic Execution OilRig|APT38|Transparent Tribe|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|APT39|Machete|Operation Wocao|Kimsuky|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound
222 T1059.004 Unix Shell Execution TeamTNT|Rocke|APT41
223 T1059.003 Windows Command Shell Execution Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|UNC2452|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1 Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1
224 T1059.002 AppleScript Execution no
225 T1059.001 PowerShell Execution Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|UNC2452|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda
226 T1567 Exfiltration Over Web Service Exfiltration APT28
227 T1497.003 Time Based Evasion Defense Evasion|Discovery no
228 T1497.002 User Activity Based Checks Defense Evasion|Discovery Darkhotel|FIN7
230 T1498.002 Reflection Amplification Impact no
231 T1498.001 Direct Network Flood Impact no
232 T1566.003 Spearphishing via Service Initial Access APT29|Ajax Security Team|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal
233 T1566.002 Spearphishing Link Initial Access Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound
234 T1566.001 Spearphishing Attachment Initial Access APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Nomadic Octopus|Tonto Team|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|APT1|FIN6|APT30|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|DarkHydrus|Lazarus Group|Gorgon Group|OilRig|BRONZE BUTLER|APT19|APT32|Cobalt Group|Rancor|FIN7|Dragonfly 2.0|MuddyWater|APT28|TA459|APT29|APT37|Leviathan|FIN8|Patchwork|menuPass|Elderwood|PLATINUM
235 T1566 Phishing Initial Access GOLD SOUTHFIELD|Dragonfly
236 T1565.003 Runtime Data Manipulation Impact APT38
250 T1087.002 Domain Account Discovery MuddyWater|Fox Kitten|Operation Wocao|Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang
251 T1087.001 Local Account Discovery Chimera|Fox Kitten|Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338
252 T1553.004 Install Root Certificate Defense Evasion no
253 T1562.004 Disable or Modify System Firewall Defense Evasion TeamTNT|APT38|APT29|UNC2452|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak TeamTNT|APT38|APT29|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak
254 T1562.003 Impair Command History Logging Defense Evasion APT38
255 T1562.002 Disable Windows Event Logging Defense Evasion Sandworm Team|APT29|UNC2452|Threat Group-3390 Sandworm Team|APT29|Threat Group-3390
256 T1562.001 Disable or Modify Tools Defense Evasion TeamTNT|Indrik Spider|APT29|MuddyWater|UNC2452|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda TeamTNT|Indrik Spider|APT29|MuddyWater|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda
257 T1562 Impair Defenses Defense Evasion no
258 T1003.004 LSA Secrets Credential Access OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390
259 T1003.005 Cached Domain Credentials Credential Access OilRig|MuddyWater|Leafminer|APT33
262 T1561 Disk Wipe Impact no
263 T1560.003 Archive via Custom Method Collection Mustang Panda|Lazarus Group|Kimsuky|CopyKittens|FIN6
264 T1560.002 Archive via Library Collection Lazarus Group|Threat Group-3390
265 T1560.001 Archive via Utility Collection APT28|APT29|Mustang Panda|HAFNIUM|UNC2452|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang APT28|APT29|Mustang Panda|HAFNIUM|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang
266 T1560 Archive Collected Data Collection Leviathan|menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang
267 T1499.004 Application or System Exploitation Impact no
268 T1499.003 Application Exhaustion Flood Impact no
271 T1491.002 External Defacement Impact Sandworm Team
272 T1491.001 Internal Defacement Impact Lazarus Group
273 T1114.003 Email Forwarding Rule Collection Silent Librarian|Kimsuky
274 T1114.002 Remote Email Collection Collection APT29|HAFNIUM|Chimera|UNC2452|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28 APT29|HAFNIUM|Chimera|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28
275 T1114.001 Local Email Collection Collection Chimera|Magic Hound|APT1
276 T1134.005 SID-History Injection Defense Evasion|Privilege Escalation no
277 T1134.004 Parent PID Spoofing Defense Evasion|Privilege Escalation no
280 T1134.001 Token Impersonation/Theft Defense Evasion|Privilege Escalation FIN8|APT28
281 T1213.002 Sharepoint Collection Chimera|Ke3chang|APT28
282 T1213.001 Confluence Collection no
283 T1555.003 Credentials from Web Browsers Credential Access Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|MuddyWater|APT37|Patchwork|Molerats
284 T1555.002 Securityd Memory Credential Access no
285 T1555.001 Keychain Credential Access no
286 T1559.002 Dynamic Data Exchange Execution Leviathan|Sidewinder|Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|FIN7|APT28
297 T1056.004 Credential API Hooking Collection|Credential Access PLATINUM
298 T1056.003 Web Portal Capture Collection|Credential Access no
299 T1056.002 GUI Input Capture Collection|Credential Access FIN4
300 T1056.001 Keylogging Collection|Credential Access Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28 Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28
301 T1555 Credentials from Password Stores Credential Access APT29|Evilnum|UNC2452|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon APT29|Evilnum|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon
302 T1552.005 Cloud Instance Metadata API Credential Access TeamTNT
303 T1003.008 /etc/passwd and /etc/shadow Credential Access no
304 T1003.007 Proc Filesystem Credential Access no
305 T1003.006 DCSync Credential Access APT29|UNC2452|Operation Wocao APT29|Operation Wocao
306 T1558.003 Kerberoasting Credential Access FIN7|APT29|UNC2452|Operation Wocao|Wizard Spider FIN7|APT29|Operation Wocao|Wizard Spider
307 T1552.006 Group Policy Preferences Credential Access APT33
308 T1003.003 NTDS Credential Access APT28|Mustang Panda|HAFNIUM|Fox Kitten|menuPass|Wizard Spider|Chimera|FIN6|Dragonfly 2.0
309 T1003.002 Security Account Manager Credential Access Wizard Spider|Threat Group-3390|Ke3chang|GALLIUM|Night Dragon|Dragonfly 2.0|menuPass
310 T1003.001 LSASS Memory Credential Access Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver
311 T1110.004 Credential Stuffing Credential Access Chimera
312 T1110.003 Password Spraying Credential Access Sandworm Team|APT29|Silent Librarian|Chimera|APT28|APT33|Leafminer|Lazarus Group
313 T1110.002 Password Cracking Credential Access FIN6|APT41|Dragonfly 2.0|APT3
314 T1110.001 Password Guessing Credential Access APT28
315 T1021.006 Windows Remote Management Lateral Movement APT29|UNC2452|Chimera|Wizard Spider|Threat Group-3390 APT29|Chimera|Wizard Spider|Threat Group-3390
316 T1021.005 VNC Lateral Movement FIN7|Fox Kitten|GCMAN
317 T1021.004 SSH Lateral Movement TeamTNT|FIN7|Fox Kitten|Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN
318 T1021.003 Distributed Component Object Model Lateral Movement no
319 T1021.002 SMB/Windows Admin Shares Lateral Movement Sandworm Team|APT28|Fox Kitten|APT41|Operation Wocao|Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang
320 T1021.001 Remote Desktop Protocol Lateral Movement Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom
321 T1554 Compromise Client Software Binary Persistence no
322 T1036.006 Space after Filename Defense Evasion no
323 T1036.005 Match Legitimate Name or Location Defense Evasion APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|UNC2452|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1 APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1
324 T1036.004 Masquerade Task or Service Defense Evasion BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|UNC2452|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7 BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7
325 T1036.003 Rename System Utilities Defense Evasion menuPass|APT32|GALLIUM
326 T1036.002 Right-to-Left Override Defense Evasion Ferocious Kitten|BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic
327 T1036.001 Invalid Code Signature Defense Evasion Windshift|APT37
328 T1553.003 SIP and Trust Provider Hijacking Defense Evasion no
329 T1553.002 Code Signing Defense Evasion menuPass|APT29|GALLIUM|UNC2452|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel menuPass|APT29|GALLIUM|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel
330 T1553.001 Gatekeeper Bypass Defense Evasion no
331 T1553 Subvert Trust Controls Defense Evasion no
332 T1027.003 Steganography Defense Evasion Andariel|Leviathan|TA551|BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37
334 T1027.001 Binary Padding Defense Evasion APT29|Mustang Panda|Higaisa|Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee
335 T1222.002 Linux and Mac File and Directory Permissions Modification Defense Evasion TeamTNT|Rocke|APT32
336 T1222.001 Windows File and Directory Permissions Modification Defense Evasion Wizard Spider
337 T1552.004 Private Keys Credential Access TeamTNT|APT29|UNC2452|Operation Wocao|Rocke TeamTNT|APT29|Operation Wocao|Rocke
338 T1552.003 Bash History Credential Access no
339 T1552.002 Credentials in Registry Credential Access APT32
340 T1552.001 Credentials In Files Credential Access TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3 TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|MuddyWater|APT3
341 T1552 Unsecured Credentials Credential Access no
342 T1216.001 PubPrn Defense Evasion APT32
343 T1070.006 Timestomp Defense Evasion APT38|APT29|UNC2452|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28 APT38|APT29|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28
344 T1070.005 Network Share Connection Removal Defense Evasion Threat Group-3390
345 T1070.004 File Deletion Defense Evasion TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|UNC2452|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29 TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29
346 T1070.003 Clear Command History Defense Evasion TeamTNT|menuPass|APT41
347 T1550.004 Web Session Cookie Defense Evasion|Lateral Movement APT29|UNC2452 APT29
348 T1550.001 Application Access Token Defense Evasion|Lateral Movement APT28
349 T1550.003 Pass the Ticket Defense Evasion|Lateral Movement APT32|BRONZE BUTLER|APT29
350 T1550.002 Pass the Hash Defense Evasion|Lateral Movement Chimera|Kimsuky|GALLIUM|APT32|Night Dragon|APT28|APT1
351 T1550 Use Alternate Authentication Material Defense Evasion|Lateral Movement APT29|UNC2452 APT29
352 T1548.004 Elevated Execution with Prompt Privilege Escalation|Defense Evasion no
353 T1548.003 Sudo and Sudo Caching Privilege Escalation|Defense Evasion no
354 T1548.002 Bypass User Account Control Privilege Escalation|Defense Evasion Evilnum|APT37|MuddyWater|Threat Group-3390|Honeybee|Cobalt Group|BRONZE BUTLER|Patchwork|APT29
382 T1546.006 LC_LOAD_DYLIB Addition Privilege Escalation|Persistence no
383 T1546.005 Trap Privilege Escalation|Persistence no
384 T1546.004 Unix Shell Configuration Modification Privilege Escalation|Persistence no
385 T1546.003 Windows Management Instrumentation Event Subscription Privilege Escalation|Persistence FIN8|Mustang Panda|UNC2452|APT33|Blue Mockingbird|Turla|Leviathan|APT29 FIN8|Mustang Panda|APT33|Blue Mockingbird|Turla|Leviathan|APT29
386 T1546.002 Screensaver Privilege Escalation|Persistence no
387 T1546.001 Change Default File Association Privilege Escalation|Persistence Kimsuky
388 T1547.001 Registry Run Keys / Startup Folder Persistence|Privilege Escalation TeamTNT|Naikon|Windshift|Mustang Panda|ZIRCONIUM|Higaisa|Sidewinder|APT28|Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Kimsuky|APT33|APT39|APT32|APT18|Dark Caracal|Threat Group-3390|Honeybee|Turla|Cobalt Group|Ke3chang|Dragonfly 2.0|APT19|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|APT3|Magic Hound|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel
393 T1218.004 InstallUtil Defense Evasion Mustang Panda|menuPass
394 T1218.001 Compiled HTML File Defense Evasion APT41|Silence|Dark Caracal|OilRig|Lazarus Group
395 T1218.003 CMSTP Defense Evasion Cobalt Group|MuddyWater
396 T1218.011 Rundll32 Defense Evasion APT38|HAFNIUM|TA551|UNC2452|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28 APT38|HAFNIUM|TA551|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28
397 T1547 Boot or Logon Autostart Execution Persistence|Privilege Escalation no
398 T1546 Event Triggered Execution Privilege Escalation|Persistence no
399 T1098.003 Add Office 365 Global Administrator Role Persistence no
400 T1098.002 Exchange Email Delegate Permissions Persistence APT28|APT29|UNC2452|Magic Hound APT28|APT29|Magic Hound
401 T1098.001 Additional Cloud Credentials Persistence APT29|UNC2452 APT29
402 T1543.004 Launch Daemon Persistence|Privilege Escalation no
403 T1543.003 Windows Service Persistence|Privilege Escalation TeamTNT|APT38|PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|FIN7|APT19|Threat Group-3390|Honeybee|APT3|Lazarus Group|Carbanak
404 T1543.002 Systemd Service Persistence|Privilege Escalation TeamTNT|Rocke
427 T1505.002 Transport Agent Persistence no
428 T1505.001 SQL Stored Procedures Persistence Sandworm Team
429 T1053.003 Cron Execution|Persistence|Privilege Escalation APT38|Rocke
T1053.004 Launchd Execution|Persistence|Privilege Escalation no
430 T1053.001 At (Linux) Execution|Persistence|Privilege Escalation no
431 T1053.005 Scheduled Task Execution|Persistence|Privilege Escalation APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|UNC2452|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29 APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29
432 T1053.002 At (Windows) Execution|Persistence|Privilege Escalation BRONZE BUTLER|Threat Group-3390|APT18
433 T1542 Pre-OS Boot Defense Evasion|Persistence no
434 T1137.001 Office Template Macros Persistence MuddyWater
463 T1486 Data Encrypted for Impact Impact FIN7|Indrik Spider|APT41|TA505|APT38
464 T1485 Data Destruction Impact Sandworm Team|Lazarus Group|APT38
465 T1484 Domain Policy Modification Defense Evasion|Privilege Escalation no
466 T1482 Domain Trust Discovery Discovery FIN8|APT29|Chimera|UNC2452 FIN8|APT29|Chimera
467 T1480 Execution Guardrails Defense Evasion no
468 T1221 Template Injection Defense Evasion Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|DarkHydrus|Dragonfly 2.0
469 T1222 File and Directory Permissions Modification Defense Evasion no
480 T1218 Signed Binary Proxy Execution Defense Evasion no
481 T1204 User Execution Execution no
482 T1213 Data from Information Repositories Collection APT28|Fox Kitten|FIN6|Turla
483 T1190 Exploit Public-Facing Application Initial Access BackdoorDiplomacy|menuPass|Volatile Cedar|UNC2452|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom BackdoorDiplomacy|menuPass|Volatile Cedar|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom
484 T1210 Exploitation of Remote Services Lateral Movement Tonto Team|FIN7|Fox Kitten|menuPass|Wizard Spider|Threat Group-3390|APT28
485 T1200 Hardware Additions Initial Access DarkVishnya
486 T1202 Indirect Command Execution Defense Evasion no
488 T1207 Rogue Domain Controller Defense Evasion no
489 T1216 Signed Script Proxy Execution Defense Evasion no
490 T1205 Traffic Signaling Defense Evasion|Persistence|Command And Control no
491 T1176 Browser Extensions Persistence Kimsuky|Stolen Pencil Kimsuky
492 T1187 Forced Authentication Credential Access DarkHydrus|Dragonfly 2.0
T1175 Component Object Model and Distributed COM Lateral Movement|Execution no
493 T1185 Browser Session Hijacking Collection no
494 T1140 Deobfuscate/Decode Files or Information Defense Evasion APT39|APT29|ZIRCONIUM|Higaisa|UNC2452|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER APT39|APT29|ZIRCONIUM|Higaisa|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER
495 T1134 Access Token Manipulation Defense Evasion|Privilege Escalation FIN6|Blue Mockingbird
T1149 LC_MAIN Hijacking Defense Evasion no
496 T1136 Create Account Persistence Sandworm Team|Indrik Spider
497 T1135 Network Share Discovery Discovery Tonto Team|APT38|Chimera|Operation Wocao|Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug
498 T1137 Office Application Startup Persistence Gamaredon Group|APT32
499 T1153 T1133 Source External Remote Services Execution Persistence|Initial Access no TeamTNT|Leviathan|APT28|APT29|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
T1133 External Remote Services Persistence|Initial Access TeamTNT|Leviathan|APT28|APT29|UNC2452|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18
500 T1132 Data Encoding Command And Control no
501 T1129 Shared Modules Execution no
502 T1127 Trusted Developer Utilities Proxy Execution Defense Evasion no
511 T1112 Modify Registry Defense Evasion Operation Wocao|Kimsuky|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Patchwork|Gorgon Group|Threat Group-3390|Dragonfly 2.0|APT19|Honeybee|FIN8
512 T1111 Two-Factor Authentication Interception Credential Access Chimera|Operation Wocao
513 T1110 Brute Force Credential Access APT38|APT28|Fox Kitten|DarkVishnya|APT39|OilRig|FIN5|Turla
T1108 Redundant Access Defense Evasion|Persistence no
514 T1106 Native API Execution APT38|Higaisa|menuPass|Operation Wocao|Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group
515 T1105 Ingress Tool Transfer Command And Control TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|UNC2452|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28 TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28
516 T1104 Multi-Stage Channels Command And Control APT41|MuddyWater|APT3
517 T1102 Web Service Command And Control TeamTNT|FIN8|Fox Kitten|Turla|APT32|Gamaredon Group|Rocke|Inception|FIN6
518 T1098 Account Manipulation Persistence Sandworm Team|APT3|Dragonfly 2.0|Lazarus Group
520 T1092 Communication Through Removable Media Command And Control APT28
521 T1091 Replication Through Removable Media Lateral Movement|Initial Access Mustang Panda|Tropic Trooper|Darkhotel|APT28
522 T1090 Proxy Command And Control Windigo|Fox Kitten|Operation Wocao|Sandworm Team|Blue Mockingbird|APT41|Turla
523 T1087 Account Discovery Discovery APT29|UNC2452 APT29
524 T1083 File and Directory Discovery Discovery APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|UNC2452|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang
525 T1082 System Information Discovery Discovery TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|UNC2452|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang
526 T1080 Taint Shared Content Lateral Movement Gamaredon Group|BRONZE BUTLER|Darkhotel
527 T1078 Valid Accounts Defense Evasion|Persistence|Privilege Escalation|Initial Access FIN7|Leviathan|APT29|Silent Librarian|UNC2452|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak FIN7|Leviathan|APT29|Silent Librarian|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak
528 T1074 Data Staged Collection Wizard Spider
529 T1072 Software Deployment Tools Execution|Lateral Movement Silence|APT32|Threat Group-1314
530 T1071 Application Layer Protocol Command And Control TeamTNT|Rocke|Magic Hound|Dragonfly 2.0
531 T1070 Indicator Removal on Host Defense Evasion APT29|UNC2452 APT29
532 T1069 Permission Groups Discovery Discovery APT29|UNC2452|TA505|APT3 APT29|TA505|APT3
533 T1068 Exploitation for Privilege Escalation Privilege Escalation Tonto Team|ZIRCONIUM|Turla|Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28
T1064 Scripting Defense Evasion|Execution no
T1062 Hypervisor Persistence no
T1061 Graphical User Interface Execution no
534 T1059 Command and Scripting Interpreter Execution APT37|Windigo|Fox Kitten|APT32|Whitefly|APT39|Dragonfly 2.0|FIN7|APT19|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang
535 T1057 Process Discovery Discovery TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|UNC2452|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang
536 T1056 Input Capture Collection|Credential Access APT39
537 T1055 Process Injection Defense Evasion|Privilege Escalation Operation Wocao|APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|Turla|APT37|Honeybee|PLATINUM
538 T1053 Scheduled Task/Job Execution|Persistence|Privilege Escalation no
539 T1052 Exfiltration Over Physical Medium Exfiltration no
T1051 Shared Webroot Lateral Movement no
540 T1049 System Network Connections Discovery Discovery TeamTNT|Andariel|BackdoorDiplomacy|Mustang Panda|MuddyWater|Chimera|Sandworm Team|Operation Wocao|Tropic Trooper|APT41|APT38|GALLIUM|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang
541 T1048 Exfiltration Over Alternative Protocol Exfiltration no
542 T1047 Windows Management Instrumentation Execution Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|UNC2452|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda
543 T1046 Network Service Scanning Discovery TeamTNT|BackdoorDiplomacy|Naikon|CostaRicto|Chimera|Fox Kitten|Operation Wocao|Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|OilRig|Cobalt Group|Leafminer|menuPass|Suckfly|FIN6|Threat Group-3390
T1043 Commonly Used Port Command And Control OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|FIN7|APT19|Dragonfly 2.0|FIN8|APT37|APT3|Magic Hound|Lazarus Group|Threat Group-3390
544 T1041 Exfiltration Over C2 Channel Exfiltration Leviathan|ZIRCONIUM|Higaisa|Chimera|APT39|Operation Wocao|Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|GALLIUM|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang
545 T1040 Network Sniffing Credential Access|Discovery Kimsuky|Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28 Kimsuky|Sandworm Team|DarkVishnya|APT33|APT28
546 T1039 Data from Network Shared Drive Collection APT28|Chimera|Fox Kitten|Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass
547 T1037 Boot or Logon Initialization Scripts Persistence|Privilege Escalation Rocke
548 T1036 Masquerading Defense Evasion APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|UNC2452|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0 APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0
T1034 Path Interception Persistence|Privilege Escalation no
549 T1033 System Owner/User Discovery Discovery APT38|Windshift|ZIRCONIUM|Sidewinder|Chimera|Sandworm Team|Operation Wocao|Wizard Spider|Frankenstein|APT41|GALLIUM|Tropic Trooper|APT39|MuddyWater|APT37|Dragonfly 2.0|APT19|APT32|Magic Hound|OilRig|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3
550 T1030 Data Transfer Size Limits Exfiltration APT28|Threat Group-3390
551 T1029 Scheduled Transfer Exfiltration Higaisa
552 T1027 Obfuscated Files or Information Defense Evasion TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|UNC2452|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28 TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28
T1026 Multiband Communication Command And Control Lazarus Group
553 T1025 Data from Removable Media Collection Turla|Gamaredon Group|APT28
554 T1021 Remote Services Lateral Movement no
555 T1020 Automated Exfiltration Exfiltration Sidewinder|Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee
556 T1018 Remote System Discovery Discovery Indrik Spider|Naikon|APT29|UNC2452|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla Indrik Spider|Naikon|APT29|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla
557 T1016 System Network Configuration Discovery Discovery TeamTNT|ZIRCONIUM|Mustang Panda|Higaisa|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|GALLIUM|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|Threat Group-3390|menuPass|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang
558 T1014 Rootkit Defense Evasion TeamTNT|Rocke|APT41|APT28|Winnti Group
559 T1012 Query Registry Discovery ZIRCONIUM|Chimera|Fox Kitten|APT39|Operation Wocao|APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla
562 T1008 Fallback Channels Command And Control FIN7|APT41|OilRig|Lazarus Group
563 T1007 System Service Discovery Discovery Indrik Spider|Chimera|Operation Wocao|BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang
564 T1006 Direct Volume Access Defense Evasion no
565 T1005 Data from Local System Collection FIN7|APT41|APT38|Andariel|APT29|Windigo|UNC2452|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang FIN7|APT41|APT38|Andariel|APT29|Windigo|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang
566 T1003 OS Credential Dumping Credential Access Tonto Team|APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom
567 T1001 Data Obfuscation Command And Control Operation Wocao|Axiom
@@ -1,48 +1 @@
{
"baselines": [
{
"name": "Previously Seen Users In CloudTrail - Update",
"id": "66ff71c2-7e01-47dd-a041-906688c9d322",
"version": 1,
"date": "2020-05-28",
"author": "Rico Valdez, Splunk",
"type": "Baseline",
"datamodel": [
"Authentication"
],
"description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.",
"search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins",
"how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.",
"known_false_positives": "none",
"references": [],
"tags": {
"analytic_story": [
"Suspicious Cloud Authentication Activities"
],
"deployments": [
"Daily Cache Updates"
],
"detections": [
"Detect AWS Console Login by User from New Country",
"Detect AWS Console Login by User from New Region",
"Detect AWS Console Login by User from New City",
"Detect AWS Console Login by New User",
"Attempted Credential Dump From Registry via Reg exe"
],
"product": [
"Splunk Security Analytics for AWS",
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"required_fields": [
"_time",
"Authentication.signature",
"Authentication.user",
"Authentication.src"
],
"security_domain": "network"
}
}
]
}
{"baselines": [{"name": "Previously Seen Users In CloudTrail - Update", "id": "66ff71c2-7e01-47dd-a041-906688c9d322", "version": 1, "date": "2020-05-28", "author": "Rico Valdez, Splunk", "type": "Baseline", "datamodel": ["Authentication"], "description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.", "search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins", "how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.", "known_false_positives": "none", "references": [], "tags": {"analytic_story": ["Suspicious Cloud Authentication Activities"], "deployments": ["Daily Cache Updates"], "detections": ["Detect AWS Console Login by User from New Country", "Detect AWS Console Login by User from New Region", "Detect AWS Console Login by User from New City", "Detect AWS Console Login by New User", "Attempted Credential Dump From Registry via Reg exe"], "product": ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Authentication.signature", "Authentication.user", "Authentication.src"], "security_domain": "network"}}]}
@@ -1,48 +1 @@
{
"baselines": [
{
"name": "Previously Seen Users In CloudTrail - Update",
"id": "66ff71c2-7e01-47dd-a041-906688c9d322",
"version": 1,
"date": "2020-05-28",
"author": "Rico Valdez, Splunk",
"type": "Baseline",
"datamodel": [
"Authentication"
],
"description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.",
"search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins",
"how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.",
"known_false_positives": "none",
"references": [],
"tags": {
"analytic_story": [
"Suspicious Cloud Authentication Activities"
],
"deployments": [
"Daily Cache Updates"
],
"detections": [
"Detect AWS Console Login by User from New Country",
"Detect AWS Console Login by User from New Region",
"Detect AWS Console Login by User from New City",
"Detect AWS Console Login by New User",
"Attempted Credential Dump From Registry via Reg exe"
],
"product": [
"Splunk Security Analytics for AWS",
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"required_fields": [
"_time",
"Authentication.signature",
"Authentication.user",
"Authentication.src"
],
"security_domain": "network"
}
}
]
}
{"baselines": [{"name": "Previously Seen Users In CloudTrail - Update", "id": "66ff71c2-7e01-47dd-a041-906688c9d322", "version": 1, "date": "2020-05-28", "author": "Rico Valdez, Splunk", "type": "Baseline", "datamodel": ["Authentication"], "description": "This search looks for CloudTrail events where a user logs into the console, then updates the baseline of the latest and earliest times, City, Region, and Country we have encountered this user in our dataset, grouped by user, within the last hour.", "search": "| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src | iplocation Authentication.src | rename Authentication.user as user Authentication.src as src | table user src City Region Country firstTime lastTime | inputlookup append=t previously_seen_users_console_logins | stats min(firstTime) as firstTime max(lastTime) as lastTime by user src City Region Country | outputlookup previously_seen_users_console_logins", "how_to_implement": "You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later) and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in `previously_seen_users_console_logins`, which is a lookup file created by this support search.", "known_false_positives": "none", "references": [], "tags": {"analytic_story": ["Suspicious Cloud Authentication Activities"], "deployments": ["Daily Cache Updates"], "detections": ["Detect AWS Console Login by User from New Country", "Detect AWS Console Login by User from New Region", "Detect AWS Console Login by User from New City", "Detect AWS Console Login by New User", "Attempted Credential Dump From Registry via Reg exe"], "product": ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Authentication.signature", "Authentication.user", "Authentication.src"], "security_domain": "network"}}]}
@@ -1,20 +1 @@
{
"deployments": [
{
"name": "ESCU Default Configuration Baseline",
"id": "0f7ee854-1aad-4bef-89c5-5c402b488510",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type baseline.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"tags": {
"type": "Baseline"
}
}
]
}
{"deployments": [{"name": "ESCU Default Configuration Baseline", "id": "0f7ee854-1aad-4bef-89c5-5c402b488510", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type baseline.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Baseline"}}]}
@@ -1,20 +1 @@
{
"deployments": [
{
"name": "ESCU Default Configuration Baseline",
"id": "0f7ee854-1aad-4bef-89c5-5c402b488510",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type baseline.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"tags": {
"type": "Baseline"
}
}
]
}
{"deployments": [{"name": "ESCU Default Configuration Baseline", "id": "0f7ee854-1aad-4bef-89c5-5c402b488510", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type baseline.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Baseline"}}]}
@@ -1,170 +1 @@
{
"detections": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
"version": 6,
"date": "2021-09-16",
"author": "Patrick Bareiss, Splunk",
"type": "TTP",
"datamodel": [
"Endpoint"
],
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
"known_false_positives": "None identified.",
"references": [
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
],
"tags": {
"name": "Attempted Credential Dump From Registry via Reg exe",
"analytic_story": [
"Credential Dumping",
"DarkSide Ransomware"
],
"asset_type": "Endpoint",
"automated_detection_testing": "passed",
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"confidence": 100,
"context": [
"Source:Endpoint",
"Stage:Credential Access"
],
"dataset": [
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
],
"impact": 90,
"kill_chain_phases": [
"Actions on Objectives"
],
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
"mitre_attack_id": [
"T1003.002",
"T1003"
],
"nist": [
"DE.CM"
],
"observable": [
{
"name": "user",
"type": "User",
"role": [
"Victim"
]
},
{
"name": "dest",
"type": "Hostname",
"role": [
"Victim"
]
},
{
"name": "parent_process_name",
"type": "Process",
"role": [
"Parent Process"
]
},
{
"name": "process_name",
"type": "Process",
"role": [
"Child Process"
]
}
],
"product": [
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"required_fields": [
"_time",
"Processes.dest",
"Processes.user",
"Processes.parent_process_name",
"Processes.parent_process",
"Processes.original_file_name",
"Processes.process_name",
"Processes.process",
"Processes.process_id",
"Processes.parent_process_path",
"Processes.process_path",
"Processes.parent_process_id"
],
"risk_score": 90,
"security_domain": "endpoint",
"risk_severity": "high",
"supported_tas": [
"Splunk_TA_microsoft_sysmon"
],
"mitre_attack_enrichments": [
{
"mitre_attack_id": "T1003.002",
"mitre_attack_technique": "Security Account Manager",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"Dragonfly 2.0",
"GALLIUM",
"Ke3chang",
"Night Dragon",
"Threat Group-3390",
"Wizard Spider",
"menuPass"
]
},
{
"mitre_attack_id": "T1003",
"mitre_attack_technique": "OS Credential Dumping",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"APT28",
"APT32",
"APT39",
"Axiom",
"Frankenstein",
"Leviathan",
"Poseidon Group",
"Sowbug",
"Suckfly",
"Tonto Team"
]
}
]
},
"macros": [
{
"name": "process_reg",
"definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)",
"description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"
},
{
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
"definition": "search *",
"description": "Update this macro to limit the output results to filter out false positives."
}
],
"lookups": [],
"cve_enrichment": [],
"splunk_app_enrichment": [
{
"name": "Splunk Add-on for Sysmon",
"url": "https://splunkbase.splunk.com/app/5709"
}
],
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
"source": "detection"
}
]
}
{"detections": [{"name": "Attempted Credential Dump From Registry via Reg exe", "id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911", "version": 6, "date": "2021-09-16", "author": "Patrick Bareiss, Splunk", "type": "TTP", "datamodel": ["Endpoint"], "description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.", "search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`", "how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.", "known_false_positives": "None identified.", "references": ["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"], "tags": {"name": "Attempted Credential Dump From Registry via Reg exe", "analytic_story": ["Credential Dumping", "DarkSide Ransomware"], "asset_type": "Endpoint", "automated_detection_testing": "passed", "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Credential Access"], "dataset": ["https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"], "impact": 90, "kill_chain_phases": ["Actions on Objectives"], "message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.", "mitre_attack_id": ["T1003.002", "T1003"], "nist": ["DE.CM"], "observable": [{"name": "user", "type": "User", "role": ["Victim"]}, {"name": "dest", "type": "Hostname", "role": ["Victim"]}, {"name": "parent_process_name", "type": "Process", "role": ["Parent Process"]}, {"name": "process_name", "type": "Process", "role": ["Child Process"]}], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Processes.dest", "Processes.user", "Processes.parent_process_name", "Processes.parent_process", "Processes.original_file_name", "Processes.process_name", "Processes.process", "Processes.process_id", "Processes.parent_process_path", "Processes.process_path", "Processes.parent_process_id"], "risk_score": 90, "security_domain": "endpoint", "risk_severity": "high", "supported_tas": ["Splunk_TA_microsoft_sysmon"], "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}]}, "macros": [{"name": "process_reg", "definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)", "description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"}, {"name": "attempted_credential_dump_from_registry_via_reg_exe_filter", "definition": "search *", "description": "Update this macro to limit the output results to filter out false positives."}], "lookups": [], "cve_enrichment": [], "splunk_app_enrichment": [{"name": "Splunk Add-on for Sysmon", "url": "https://splunkbase.splunk.com/app/5709"}], "file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml", "source": "detection"}]}
@@ -1,168 +1 @@
{
"detections": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
"version": 6,
"date": "2021-09-16",
"author": "Patrick Bareiss, Splunk",
"type": "TTP",
"datamodel": [
"Endpoint"
],
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
"known_false_positives": "None identified.",
"references": [
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
],
"tags": {
"name": "Attempted Credential Dump From Registry via Reg exe",
"analytic_story": [
"Credential Dumping",
"DarkSide Ransomware"
],
"asset_type": "Endpoint",
"automated_detection_testing": "passed",
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"confidence": 100,
"context": [
"Source:Endpoint",
"Stage:Credential Access"
],
"dataset": [
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
],
"impact": 90,
"kill_chain_phases": [
"Actions on Objectives"
],
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
"mitre_attack_id": [
"T1003.002",
"T1003"
],
"nist": [
"DE.CM"
],
"observable": [
{
"name": "user",
"type": "User",
"role": [
"Victim"
]
},
{
"name": "dest",
"type": "Hostname",
"role": [
"Victim"
]
},
{
"name": "parent_process_name",
"type": "Process",
"role": [
"Parent Process"
]
},
{
"name": "process_name",
"type": "Process",
"role": [
"Child Process"
]
}
],
"product": [
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"required_fields": [
"_time",
"Processes.dest",
"Processes.user",
"Processes.parent_process_name",
"Processes.parent_process",
"Processes.original_file_name",
"Processes.process_name",
"Processes.process",
"Processes.process_id",
"Processes.parent_process_path",
"Processes.process_path",
"Processes.parent_process_id"
],
"risk_score": 90,
"security_domain": "endpoint",
"risk_severity": "high",
"supported_tas": [
"Splunk_TA_microsoft_sysmon"
],
"mitre_attack_enrichments": [
{
"mitre_attack_id": "T1003.002",
"mitre_attack_technique": "Security Account Manager",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"Dragonfly 2.0",
"Ke3chang",
"Night Dragon",
"Soft Cell",
"Threat Group-3390",
"menuPass"
]
},
{
"mitre_attack_id": "T1003",
"mitre_attack_technique": "OS Credential Dumping",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"APT28",
"APT32",
"APT39",
"Axiom",
"Frankenstein",
"Leviathan",
"Poseidon Group",
"Sowbug",
"Suckfly"
]
}
]
},
"macros": [
{
"name": "process_reg",
"definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)",
"description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"
},
{
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
"definition": "search *",
"description": "Update this macro to limit the output results to filter out false positives."
}
],
"lookups": [],
"cve_enrichment": [],
"splunk_app_enrichment": [
{
"name": "Splunk Add-on for Sysmon",
"url": "https://splunkbase.splunk.com/app/5709"
}
],
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
"source": "detection"
}
]
}
{"detections": [{"name": "Attempted Credential Dump From Registry via Reg exe", "id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911", "version": 6, "date": "2021-09-16", "author": "Patrick Bareiss, Splunk", "type": "TTP", "datamodel": ["Endpoint"], "description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.", "search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`", "how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.", "known_false_positives": "None identified.", "references": ["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"], "tags": {"name": "Attempted Credential Dump From Registry via Reg exe", "analytic_story": ["Credential Dumping", "DarkSide Ransomware"], "asset_type": "Endpoint", "automated_detection_testing": "passed", "cis20": ["CIS 3", "CIS 5", "CIS 16"], "confidence": 100, "context": ["Source:Endpoint", "Stage:Credential Access"], "dataset": ["https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"], "impact": 90, "kill_chain_phases": ["Actions on Objectives"], "message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.", "mitre_attack_id": ["T1003.002", "T1003"], "nist": ["DE.CM"], "observable": [{"name": "user", "type": "User", "role": ["Victim"]}, {"name": "dest", "type": "Hostname", "role": ["Victim"]}, {"name": "parent_process_name", "type": "Process", "role": ["Parent Process"]}, {"name": "process_name", "type": "Process", "role": ["Child Process"]}], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "required_fields": ["_time", "Processes.dest", "Processes.user", "Processes.parent_process_name", "Processes.parent_process", "Processes.original_file_name", "Processes.process_name", "Processes.process", "Processes.process_id", "Processes.parent_process_path", "Processes.process_path", "Processes.parent_process_id"], "risk_score": 90, "security_domain": "endpoint", "risk_severity": "high", "supported_tas": ["Splunk_TA_microsoft_sysmon"], "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}]}, "macros": [{"name": "process_reg", "definition": "(Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe)", "description": "Matches the process with its original file name, data for this macro came from https://strontic.github.io/"}, {"name": "attempted_credential_dump_from_registry_via_reg_exe_filter", "definition": "search *", "description": "Update this macro to limit the output results to filter out false positives."}], "lookups": [], "cve_enrichment": [], "splunk_app_enrichment": [{"name": "Splunk Add-on for Sysmon", "url": "https://splunkbase.splunk.com/app/5709"}], "file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml", "source": "detection"}]}
@@ -1,11 +1 @@
{
"lookups": [
{
"name": "previously_seen_aws_regions",
"description": "A place holder for a list of used AWS regions",
"filename": "previously_seen_aws_regions.csv",
"default_match": "false",
"min_matches": 1
}
]
}
{"lookups": [{"name": "previously_seen_aws_regions", "description": "A place holder for a list of used AWS regions", "filename": "previously_seen_aws_regions.csv", "default_match": "false", "min_matches": 1}]}
@@ -1,11 +1 @@
{
"lookups": [
{
"name": "previously_seen_aws_regions",
"description": "A place holder for a list of used AWS regions",
"filename": "previously_seen_aws_regions.csv",
"default_match": "false",
"min_matches": 1
}
]
}
{"lookups": [{"name": "previously_seen_aws_regions", "description": "A place holder for a list of used AWS regions", "filename": "previously_seen_aws_regions.csv", "default_match": "false", "min_matches": 1}]}
@@ -1,9 +1 @@
{
"macros": [
{
"name": "powershell",
"definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")",
"description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."
}
]
}
{"macros": [{"name": "powershell", "definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")", "description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."}]}
@@ -1,9 +1 @@
{
"macros": [
{
"name": "powershell",
"definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")",
"description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."
}
]
}
{"macros": [{"name": "powershell", "definition": "(source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source=\"XmlWinEventLog:Microsoft-Windows-PowerShell/Operational\")", "description": "customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent."}]}
@@ -1,69 +1 @@
{
"response_tasks": [
{
"name": "Get Parent Process Info",
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
"version": 2,
"date": "2019-02-28",
"author": "Bhavin Patel, Splunk",
"type": "Investigation",
"datamodel": [
"Endpoint"
],
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
"known_false_positives": "",
"references": [],
"inputs": [
"parent_process_name",
"dest"
],
"tags": {
"analytic_story": [
"Collection and Staging",
"Command and Control",
"DHS Report TA18-074A",
"Disabling Security Tools",
"Emotet Malware DHS Report TA18-201A ",
"Hidden Cobra Malware",
"Lateral Movement",
"Malicious PowerShell",
"Monitor for Unauthorized Software",
"Netsh Abuse",
"Orangeworm Attack Group",
"Phishing Payloads",
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
"Prohibited Traffic Allowed or Protocol Mismatch",
"Ransomware",
"SamSam Ransomware",
"Suspicious Command-Line Executions",
"Suspicious DNS Traffic",
"Suspicious MSHTA Activity",
"Suspicious WMI Use",
"Suspicious Windows Registry Activities",
"Unusual Processes",
"Windows Defense Evasion Tactics",
"Windows File Extension and Association Abuse",
"Windows Log Manipulation",
"Windows Persistence Techniques",
"Windows Privilege Escalation",
"Windows Service Abuse",
"DarkSide Ransomware"
],
"product": [
"Splunk Phantom"
],
"required_fields": [
"_time",
"Processes.user",
"Processes.parent_process_name",
"Processes.process_name",
"Processes.dest"
],
"security_domain": "endpoint"
},
"lowercase_name": "get_parent_process_info"
}
]
}
{"response_tasks": [{"name": "Get Parent Process Info", "id": "fecf2918-670d-4f1c-872b-3d7317a41bf9", "version": 2, "date": "2019-02-28", "author": "Bhavin Patel, Splunk", "type": "Investigation", "datamodel": ["Endpoint"], "description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest", "search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`", "how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.", "known_false_positives": "", "references": [], "inputs": ["parent_process_name", "dest"], "tags": {"analytic_story": ["Collection and Staging", "Command and Control", "DHS Report TA18-074A", "Disabling Security Tools", "Emotet Malware DHS Report TA18-201A ", "Hidden Cobra Malware", "Lateral Movement", "Malicious PowerShell", "Monitor for Unauthorized Software", "Netsh Abuse", "Orangeworm Attack Group", "Phishing Payloads", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Prohibited Traffic Allowed or Protocol Mismatch", "Ransomware", "SamSam Ransomware", "Suspicious Command-Line Executions", "Suspicious DNS Traffic", "Suspicious MSHTA Activity", "Suspicious WMI Use", "Suspicious Windows Registry Activities", "Unusual Processes", "Windows Defense Evasion Tactics", "Windows File Extension and Association Abuse", "Windows Log Manipulation", "Windows Persistence Techniques", "Windows Privilege Escalation", "Windows Service Abuse", "DarkSide Ransomware"], "product": ["Splunk Phantom"], "required_fields": ["_time", "Processes.user", "Processes.parent_process_name", "Processes.process_name", "Processes.dest"], "security_domain": "endpoint"}, "lowercase_name": "get_parent_process_info"}]}
@@ -1,69 +1 @@
{
"response_tasks": [
{
"name": "Get Parent Process Info",
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
"version": 2,
"date": "2019-02-28",
"author": "Bhavin Patel, Splunk",
"type": "Investigation",
"datamodel": [
"Endpoint"
],
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
"known_false_positives": "",
"references": [],
"inputs": [
"parent_process_name",
"dest"
],
"tags": {
"analytic_story": [
"Collection and Staging",
"Command and Control",
"DHS Report TA18-074A",
"Disabling Security Tools",
"Emotet Malware DHS Report TA18-201A ",
"Hidden Cobra Malware",
"Lateral Movement",
"Malicious PowerShell",
"Monitor for Unauthorized Software",
"Netsh Abuse",
"Orangeworm Attack Group",
"Phishing Payloads",
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
"Prohibited Traffic Allowed or Protocol Mismatch",
"Ransomware",
"SamSam Ransomware",
"Suspicious Command-Line Executions",
"Suspicious DNS Traffic",
"Suspicious MSHTA Activity",
"Suspicious WMI Use",
"Suspicious Windows Registry Activities",
"Unusual Processes",
"Windows Defense Evasion Tactics",
"Windows File Extension and Association Abuse",
"Windows Log Manipulation",
"Windows Persistence Techniques",
"Windows Privilege Escalation",
"Windows Service Abuse",
"DarkSide Ransomware"
],
"product": [
"Splunk Phantom"
],
"required_fields": [
"_time",
"Processes.user",
"Processes.parent_process_name",
"Processes.process_name",
"Processes.dest"
],
"security_domain": "endpoint"
},
"lowercase_name": "get_parent_process_info"
}
]
}
{"response_tasks": [{"name": "Get Parent Process Info", "id": "fecf2918-670d-4f1c-872b-3d7317a41bf9", "version": 2, "date": "2019-02-28", "author": "Bhavin Patel, Splunk", "type": "Investigation", "datamodel": ["Endpoint"], "description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest", "search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`", "how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.", "known_false_positives": "", "references": [], "inputs": ["parent_process_name", "dest"], "tags": {"analytic_story": ["Collection and Staging", "Command and Control", "DHS Report TA18-074A", "Disabling Security Tools", "Emotet Malware DHS Report TA18-201A ", "Hidden Cobra Malware", "Lateral Movement", "Malicious PowerShell", "Monitor for Unauthorized Software", "Netsh Abuse", "Orangeworm Attack Group", "Phishing Payloads", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Prohibited Traffic Allowed or Protocol Mismatch", "Ransomware", "SamSam Ransomware", "Suspicious Command-Line Executions", "Suspicious DNS Traffic", "Suspicious MSHTA Activity", "Suspicious WMI Use", "Suspicious Windows Registry Activities", "Unusual Processes", "Windows Defense Evasion Tactics", "Windows File Extension and Association Abuse", "Windows Log Manipulation", "Windows Persistence Techniques", "Windows Privilege Escalation", "Windows Service Abuse", "DarkSide Ransomware"], "product": ["Splunk Phantom"], "required_fields": ["_time", "Processes.user", "Processes.parent_process_name", "Processes.process_name", "Processes.dest"], "security_domain": "endpoint"}, "lowercase_name": "get_parent_process_info"}]}
@@ -1,508 +1 @@
{
"stories": [
{
"name": "DarkSide Ransomware",
"id": "507edc74-13d5-4339-878e-b9114ded1f35",
"version": 1,
"date": "2021-05-12",
"author": "Bhavin Patel, Splunk",
"description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware",
"narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.",
"references": [
"https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/",
"https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"
],
"tags": {
"name": "DarkSide Ransomware",
"analytic_story": "DarkSide Ransomware",
"category": [
"Malware"
],
"product": [
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"usecase": "Advanced Threat Detection",
"mitre_attack_enrichments": [
{
"mitre_attack_id": "T1003.002",
"mitre_attack_technique": "Security Account Manager",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"Dragonfly 2.0",
"GALLIUM",
"Ke3chang",
"Night Dragon",
"Threat Group-3390",
"Wizard Spider",
"menuPass"
]
},
{
"mitre_attack_id": "T1003",
"mitre_attack_technique": "OS Credential Dumping",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"APT28",
"APT32",
"APT39",
"Axiom",
"Frankenstein",
"Leviathan",
"Poseidon Group",
"Sowbug",
"Suckfly",
"Tonto Team"
]
}
],
"mitre_attack_tactics": [
"Credential Access"
],
"datamodels": [
"Endpoint"
],
"kill_chain_phases": [
"Actions on Objectives"
]
},
"detection_names": [
"ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"
],
"investigation_names": [
"ESCU - Get Parent Process Info - Response Task"
],
"baseline_names": [
"ESCU - Baseline Of Cloud Instances Launched"
],
"author_company": "Splunk",
"author_name": "Bhavin Patel",
"detections": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
"version": 6,
"date": "2021-09-16",
"author": "Patrick Bareiss, Splunk",
"type": "TTP",
"datamodel": [
"Endpoint"
],
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
"known_false_positives": "None identified.",
"references": [
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
],
"tags": {
"name": "Attempted Credential Dump From Registry via Reg exe",
"analytic_story": [
"Credential Dumping",
"DarkSide Ransomware"
],
"asset_type": "Endpoint",
"automated_detection_testing": "passed",
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"confidence": 100,
"context": [
"Source:Endpoint",
"Stage:Credential Access"
],
"dataset": [
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
],
"impact": 90,
"kill_chain_phases": [
"Actions on Objectives"
],
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
"mitre_attack_id": [
"T1003.002",
"T1003"
],
"nist": [
"DE.CM"
],
"observable": [
{
"name": "user",
"type": "User",
"role": [
"Victim"
]
},
{
"name": "dest",
"type": "Hostname",
"role": [
"Victim"
]
},
{
"name": "parent_process_name",
"type": "Process",
"role": [
"Parent Process"
]
},
{
"name": "process_name",
"type": "Process",
"role": [
"Child Process"
]
}
],
"product": [
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"required_fields": [
"_time",
"Processes.dest",
"Processes.user",
"Processes.parent_process_name",
"Processes.parent_process",
"Processes.original_file_name",
"Processes.process_name",
"Processes.process",
"Processes.process_id",
"Processes.parent_process_path",
"Processes.process_path",
"Processes.parent_process_id"
],
"risk_score": 90,
"security_domain": "endpoint",
"risk_severity": "high",
"supported_tas": [
"Splunk_TA_microsoft_sysmon"
],
"mitre_attack_enrichments": [
{
"mitre_attack_id": "T1003.002",
"mitre_attack_technique": "Security Account Manager",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"Dragonfly 2.0",
"GALLIUM",
"Ke3chang",
"Night Dragon",
"Threat Group-3390",
"Wizard Spider",
"menuPass"
]
},
{
"mitre_attack_id": "T1003",
"mitre_attack_technique": "OS Credential Dumping",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"APT28",
"APT32",
"APT39",
"Axiom",
"Frankenstein",
"Leviathan",
"Poseidon Group",
"Sowbug",
"Suckfly",
"Tonto Team"
]
}
]
},
"deprecated": false,
"experimental": false,
"deployment": {
"name": "ESCU Default Configuration TTP",
"id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"notable": {
"rule_description": "%description%",
"rule_title": "%name%",
"nes_fields": [
"user",
"dest"
]
},
"rba": {
"enabled": "true"
},
"tags": {
"type": "TTP"
}
},
"annotations": {
"mitre_attack": [
"T1003.002",
"T1003"
],
"kill_chain_phases": [
"Actions on Objectives"
],
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"nist": [
"DE.CM"
],
"analytic_story": [
"Credential Dumping",
"DarkSide Ransomware"
],
"observable": [
{
"name": "user",
"type": "User",
"role": [
"Victim"
]
},
{
"name": "dest",
"type": "Hostname",
"role": [
"Victim"
]
},
{
"name": "parent_process_name",
"type": "Process",
"role": [
"Parent Process"
]
},
{
"name": "process_name",
"type": "Process",
"role": [
"Child Process"
]
}
],
"context": [
"Source:Endpoint",
"Stage:Credential Access"
],
"impact": 90,
"confidence": 100
},
"risk": [
{
"risk_object_type": "user",
"risk_object_field": "user",
"risk_score": 90
},
{
"risk_object_type": "system",
"risk_object_field": "dest",
"risk_score": 90
},
{
"threat_object_field": "parent_process_name",
"threat_object_type": "process"
},
{
"threat_object_field": "process_name",
"threat_object_type": "process"
}
],
"playbooks": [
{
"name": "Ransomware Investigate and Contain",
"id": "fc0edc96-ff2b-48b0-9f6f-63da3783fd63",
"version": 1,
"date": "2018-02-04",
"author": "Philip Royer, Splunk",
"type": "Response",
"description": "This playbook investigates and contains ransomware detected on endpoints.",
"how_to_implement": "This playbook requires the Splunk SOAR apps for Palo Alto Networks Firewalls, Palo Alto Wildfire, LDAP, and Carbon Black Response.",
"playbook": "ransomware_investigate_and_contain",
"references": [],
"app_list": [
"Carbon Black Response",
"LDAP",
"Palo Alto Networks Firewall",
"WildFire",
"Cylance"
],
"tags": {
"analytic_story": [
"Ransomware"
],
"detections": [
"Attempted Credential Dump From Registry via Reg exe"
],
"platform_tags": [
"Ransomware",
"Response"
],
"playbook_fields": [
"ComputerName",
"Username"
],
"product": [
"Splunk SOAR"
],
"detection_objects": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"lowercase_name": "attempted_credential_dump_from_registry_via_reg_exe",
"path": "detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"
}
]
}
}
],
"baselines": [],
"mappings": {
"mitre_attack": [
"T1003.002",
"T1003"
],
"kill_chain_phases": [
"Actions on Objectives"
],
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"nist": [
"DE.CM"
]
},
"test": {
"name": "Attempted Credential Dump From Registry via Reg exe Unit Test",
"tests": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"file": "endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml",
"pass_condition": "| stats count | where count > 0",
"earliest_time": "-24h",
"latest_time": "now",
"attack_data": [
{
"file_name": "windows-sysmon.log",
"data": "https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log",
"source": "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational",
"sourcetype": "xmlwineventlog"
}
]
}
]
},
"macros": [
{
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
"definition": "search *",
"description": "Update this macro to limit the output results to filter out false positives."
}
],
"lookups": [],
"cve_enrichment": [],
"splunk_app_enrichment": [
{
"name": "Splunk Add-on for Sysmon",
"url": "https://splunkbase.splunk.com/app/5709"
}
],
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
"source": "detection"
}
],
"investigations": [
{
"name": "Get Parent Process Info",
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
"version": 2,
"date": "2019-02-28",
"author": "Bhavin Patel, Splunk",
"type": "Investigation",
"datamodel": [
"Endpoint"
],
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
"known_false_positives": "",
"references": [],
"inputs": [
"parent_process_name",
"dest"
],
"tags": {
"analytic_story": [
"Collection and Staging",
"Command and Control",
"DHS Report TA18-074A",
"Disabling Security Tools",
"Emotet Malware DHS Report TA18-201A ",
"Hidden Cobra Malware",
"Lateral Movement",
"Malicious PowerShell",
"Monitor for Unauthorized Software",
"Netsh Abuse",
"Orangeworm Attack Group",
"Phishing Payloads",
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
"Prohibited Traffic Allowed or Protocol Mismatch",
"Ransomware",
"SamSam Ransomware",
"Suspicious Command-Line Executions",
"Suspicious DNS Traffic",
"Suspicious MSHTA Activity",
"Suspicious WMI Use",
"Suspicious Windows Registry Activities",
"Unusual Processes",
"Windows Defense Evasion Tactics",
"Windows File Extension and Association Abuse",
"Windows Log Manipulation",
"Windows Persistence Techniques",
"Windows Privilege Escalation",
"Windows Service Abuse",
"DarkSide Ransomware"
],
"product": [
"Splunk Phantom"
],
"required_fields": [
"_time",
"Processes.user",
"Processes.parent_process_name",
"Processes.process_name",
"Processes.dest"
],
"security_domain": "endpoint"
},
"lowercase_name": "get_parent_process_info"
}
]
}
]
}
{"stories": [{"name": "DarkSide Ransomware", "id": "507edc74-13d5-4339-878e-b9114ded1f35", "version": 1, "date": "2021-05-12", "author": "Bhavin Patel, Splunk", "description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware", "narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.", "references": ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"], "tags": {"name": "DarkSide Ransomware", "analytic_story": "DarkSide Ransomware", "category": ["Malware"], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "usecase": "Advanced Threat Detection", "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}], "mitre_attack_tactics": ["Credential Access"], "datamodels": ["Endpoint"], "kill_chain_phases": ["Actions on Objectives"]}, "detection_names": ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"], "investigation_names": ["ESCU - Get Parent Process Info - Response Task"], "baseline_names": ["ESCU - Baseline Of Cloud Instances Launched"], "author_company": "Splunk", "author_name": "Bhavin Patel"}]}
@@ -1,504 +1 @@
{
"stories": [
{
"name": "DarkSide Ransomware",
"id": "507edc74-13d5-4339-878e-b9114ded1f35",
"version": 1,
"date": "2021-05-12",
"author": "Bhavin Patel, Splunk",
"description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware",
"narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.",
"references": [
"https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/",
"https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"
],
"tags": {
"name": "DarkSide Ransomware",
"analytic_story": "DarkSide Ransomware",
"category": [
"Malware"
],
"product": [
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"usecase": "Advanced Threat Detection",
"mitre_attack_enrichments": [
{
"mitre_attack_id": "T1003.002",
"mitre_attack_technique": "Security Account Manager",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"Dragonfly 2.0",
"Ke3chang",
"Night Dragon",
"Soft Cell",
"Threat Group-3390",
"menuPass"
]
},
{
"mitre_attack_id": "T1003",
"mitre_attack_technique": "OS Credential Dumping",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"APT28",
"APT32",
"APT39",
"Axiom",
"Frankenstein",
"Leviathan",
"Poseidon Group",
"Sowbug",
"Suckfly"
]
}
],
"mitre_attack_tactics": [
"Credential Access"
],
"datamodels": [
"Endpoint"
],
"kill_chain_phases": [
"Actions on Objectives"
]
},
"detection_names": [
"ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"
],
"investigation_names": [
"ESCU - Get Parent Process Info - Response Task"
],
"baseline_names": [
"ESCU - Baseline Of Cloud Instances Launched"
],
"author_company": "Splunk",
"author_name": "Bhavin Patel",
"detections": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"id": "e9fb4a59-c5fb-440a-9f24-191fbc6b2911",
"version": 6,
"date": "2021-09-16",
"author": "Patrick Bareiss, Splunk",
"type": "TTP",
"datamodel": [
"Endpoint"
],
"description": "Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline.",
"search": "| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\\\System* OR Processes.process=*HKLM\\\\Security* OR Processes.process=*HKLM\\\\System* OR Processes.process=*HKLM\\\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`",
"how_to_implement": "To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.",
"known_false_positives": "None identified.",
"references": [
"https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"
],
"tags": {
"name": "Attempted Credential Dump From Registry via Reg exe",
"analytic_story": [
"Credential Dumping",
"DarkSide Ransomware"
],
"asset_type": "Endpoint",
"automated_detection_testing": "passed",
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"confidence": 100,
"context": [
"Source:Endpoint",
"Stage:Credential Access"
],
"dataset": [
"https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log"
],
"impact": 90,
"kill_chain_phases": [
"Actions on Objectives"
],
"message": "An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.",
"mitre_attack_id": [
"T1003.002",
"T1003"
],
"nist": [
"DE.CM"
],
"observable": [
{
"name": "user",
"type": "User",
"role": [
"Victim"
]
},
{
"name": "dest",
"type": "Hostname",
"role": [
"Victim"
]
},
{
"name": "parent_process_name",
"type": "Process",
"role": [
"Parent Process"
]
},
{
"name": "process_name",
"type": "Process",
"role": [
"Child Process"
]
}
],
"product": [
"Splunk Enterprise",
"Splunk Enterprise Security",
"Splunk Cloud"
],
"required_fields": [
"_time",
"Processes.dest",
"Processes.user",
"Processes.parent_process_name",
"Processes.parent_process",
"Processes.original_file_name",
"Processes.process_name",
"Processes.process",
"Processes.process_id",
"Processes.parent_process_path",
"Processes.process_path",
"Processes.parent_process_id"
],
"risk_score": 90,
"security_domain": "endpoint",
"risk_severity": "high",
"supported_tas": [
"Splunk_TA_microsoft_sysmon"
],
"mitre_attack_enrichments": [
{
"mitre_attack_id": "T1003.002",
"mitre_attack_technique": "Security Account Manager",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"Dragonfly 2.0",
"Ke3chang",
"Night Dragon",
"Soft Cell",
"Threat Group-3390",
"menuPass"
]
},
{
"mitre_attack_id": "T1003",
"mitre_attack_technique": "OS Credential Dumping",
"mitre_attack_tactics": [
"Credential Access"
],
"mitre_attack_groups": [
"APT28",
"APT32",
"APT39",
"Axiom",
"Frankenstein",
"Leviathan",
"Poseidon Group",
"Sowbug",
"Suckfly"
]
}
]
},
"deprecated": false,
"experimental": false,
"deployment": {
"name": "ESCU Default Configuration TTP",
"id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"notable": {
"rule_description": "%description%",
"rule_title": "%name%",
"nes_fields": [
"user",
"dest"
]
},
"rba": {
"enabled": "true"
},
"tags": {
"type": "TTP"
}
},
"annotations": {
"mitre_attack": [
"T1003.002",
"T1003"
],
"kill_chain_phases": [
"Actions on Objectives"
],
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"nist": [
"DE.CM"
],
"analytic_story": [
"Credential Dumping",
"DarkSide Ransomware"
],
"observable": [
{
"name": "user",
"type": "User",
"role": [
"Victim"
]
},
{
"name": "dest",
"type": "Hostname",
"role": [
"Victim"
]
},
{
"name": "parent_process_name",
"type": "Process",
"role": [
"Parent Process"
]
},
{
"name": "process_name",
"type": "Process",
"role": [
"Child Process"
]
}
],
"context": [
"Source:Endpoint",
"Stage:Credential Access"
],
"impact": 90,
"confidence": 100
},
"risk": [
{
"risk_object_type": "user",
"risk_object_field": "user",
"risk_score": 90
},
{
"risk_object_type": "system",
"risk_object_field": "dest",
"risk_score": 90
},
{
"threat_object_field": "parent_process_name",
"threat_object_type": "process"
},
{
"threat_object_field": "process_name",
"threat_object_type": "process"
}
],
"playbooks": [
{
"name": "Ransomware Investigate and Contain",
"id": "fc0edc96-ff2b-48b0-9f6f-63da3783fd63",
"version": 1,
"date": "2018-02-04",
"author": "Philip Royer, Splunk",
"type": "Response",
"description": "This playbook investigates and contains ransomware detected on endpoints.",
"how_to_implement": "This playbook requires the Splunk SOAR apps for Palo Alto Networks Firewalls, Palo Alto Wildfire, LDAP, and Carbon Black Response.",
"playbook": "ransomware_investigate_and_contain",
"references": [],
"app_list": [
"Carbon Black Response",
"LDAP",
"Palo Alto Networks Firewall",
"WildFire",
"Cylance"
],
"tags": {
"analytic_story": [
"Ransomware"
],
"detections": [
"Attempted Credential Dump From Registry via Reg exe"
],
"platform_tags": [
"Ransomware",
"Response"
],
"playbook_fields": [
"ComputerName",
"Username"
],
"product": [
"Splunk SOAR"
],
"detection_objects": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"lowercase_name": "attempted_credential_dump_from_registry_via_reg_exe",
"path": "detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"
}
]
}
}
],
"baselines": [],
"mappings": {
"mitre_attack": [
"T1003.002",
"T1003"
],
"kill_chain_phases": [
"Actions on Objectives"
],
"cis20": [
"CIS 3",
"CIS 5",
"CIS 16"
],
"nist": [
"DE.CM"
]
},
"test": {
"name": "Attempted Credential Dump From Registry via Reg exe Unit Test",
"tests": [
{
"name": "Attempted Credential Dump From Registry via Reg exe",
"file": "endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml",
"pass_condition": "| stats count | where count > 0",
"earliest_time": "-24h",
"latest_time": "now",
"attack_data": [
{
"file_name": "windows-sysmon.log",
"data": "https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log",
"source": "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational",
"sourcetype": "xmlwineventlog"
}
]
}
]
},
"macros": [
{
"name": "attempted_credential_dump_from_registry_via_reg_exe_filter",
"definition": "search *",
"description": "Update this macro to limit the output results to filter out false positives."
}
],
"lookups": [],
"cve_enrichment": [],
"splunk_app_enrichment": [
{
"name": "Splunk Add-on for Sysmon",
"url": "https://splunkbase.splunk.com/app/5709"
}
],
"file_path": "/Users/pbareib/Documents/Projects/security_content/bin/contentctl_project/contentctl_infrastructure/tests/adapter/../builder/test_data/detection/valid.yml",
"source": "detection"
}
],
"investigations": [
{
"name": "Get Parent Process Info",
"id": "fecf2918-670d-4f1c-872b-3d7317a41bf9",
"version": 2,
"date": "2019-02-28",
"author": "Bhavin Patel, Splunk",
"type": "Investigation",
"datamodel": [
"Endpoint"
],
"description": "This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest",
"search": "| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name(\"Processes\")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`",
"how_to_implement": "You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the \"process\" field in the Endpoint data model.",
"known_false_positives": "",
"references": [],
"inputs": [
"parent_process_name",
"dest"
],
"tags": {
"analytic_story": [
"Collection and Staging",
"Command and Control",
"DHS Report TA18-074A",
"Disabling Security Tools",
"Emotet Malware DHS Report TA18-201A ",
"Hidden Cobra Malware",
"Lateral Movement",
"Malicious PowerShell",
"Monitor for Unauthorized Software",
"Netsh Abuse",
"Orangeworm Attack Group",
"Phishing Payloads",
"Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns",
"Prohibited Traffic Allowed or Protocol Mismatch",
"Ransomware",
"SamSam Ransomware",
"Suspicious Command-Line Executions",
"Suspicious DNS Traffic",
"Suspicious MSHTA Activity",
"Suspicious WMI Use",
"Suspicious Windows Registry Activities",
"Unusual Processes",
"Windows Defense Evasion Tactics",
"Windows File Extension and Association Abuse",
"Windows Log Manipulation",
"Windows Persistence Techniques",
"Windows Privilege Escalation",
"Windows Service Abuse",
"DarkSide Ransomware"
],
"product": [
"Splunk Phantom"
],
"required_fields": [
"_time",
"Processes.user",
"Processes.parent_process_name",
"Processes.process_name",
"Processes.dest"
],
"security_domain": "endpoint"
},
"lowercase_name": "get_parent_process_info"
}
]
}
]
}
{"stories": [{"name": "DarkSide Ransomware", "id": "507edc74-13d5-4339-878e-b9114ded1f35", "version": 1, "date": "2021-05-12", "author": "Bhavin Patel, Splunk", "description": "Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware", "narrative": "This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.", "references": ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"], "tags": {"name": "DarkSide Ransomware", "analytic_story": "DarkSide Ransomware", "category": ["Malware"], "product": ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"], "usecase": "Advanced Threat Detection", "mitre_attack_enrichments": [{"mitre_attack_id": "T1003.002", "mitre_attack_technique": "Security Account Manager", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["Dragonfly 2.0", "GALLIUM", "Ke3chang", "Night Dragon", "Threat Group-3390", "Wizard Spider", "menuPass"]}, {"mitre_attack_id": "T1003", "mitre_attack_technique": "OS Credential Dumping", "mitre_attack_tactics": ["Credential Access"], "mitre_attack_groups": ["APT28", "APT32", "APT39", "Axiom", "Frankenstein", "Leviathan", "Poseidon Group", "Sowbug", "Suckfly", "Tonto Team"]}], "mitre_attack_tactics": ["Credential Access"], "datamodels": ["Endpoint"], "kill_chain_phases": ["Actions on Objectives"]}, "detection_names": ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule"], "investigation_names": ["ESCU - Get Parent Process Info - Response Task"], "baseline_names": ["ESCU - Baseline Of Cloud Instances Launched"], "author_company": "Splunk", "author_name": "Bhavin Patel"}]}
+1 -2405
View File
File diff suppressed because one or more lines are too long
+1 -103
View File
@@ -1,103 +1 @@
{
"deployments": [
{
"name": "ESCU Default Configuration Anomaly",
"id": "a9e210c6-9f50-4f8b-b60e-71bb26e4f216",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type anomaly. These detections will use Risk Based Alerting.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"rba": {
"enabled": "true"
},
"tags": {
"type": "Anomaly",
"product": "ESCU"
}
},
{
"name": "ESCU Default Configuration Baseline",
"id": "0f7ee854-1aad-4bef-89c5-5c402b488510",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type baseline.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"tags": {
"type": "Baseline"
}
},
{
"name": "ESCU Default Configuration Correlation",
"id": "36ba498c-46e8-4b62-8bde-67e984a40fb4",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type Correlation. These correlations will generate Notable Events.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"notable": {
"rule_description": "%description%",
"rule_title": "%name%",
"nes_fields": []
},
"tags": {
"type": "Correlation",
"product": "ESCU"
}
},
{
"name": "ESCU Default Configuration Hunting",
"id": "cc5895e8-3420-4ab7-af38-cf87a28f9c3b",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type hunting.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"tags": {
"type": "Hunting",
"product": "ESCU"
}
},
{
"name": "ESCU Default Configuration TTP",
"id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b",
"date": "2021-12-21",
"author": "Patrick Bareiss",
"description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.",
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m",
"schedule_window": "auto"
},
"notable": {
"rule_description": "%description%",
"rule_title": "%name%",
"nes_fields": []
},
"rba": {
"enabled": "true"
},
"tags": {
"type": "TTP"
}
}
]
}
{"deployments": [{"name": "ESCU Default Configuration Anomaly", "id": "a9e210c6-9f50-4f8b-b60e-71bb26e4f216", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type anomaly. These detections will use Risk Based Alerting.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "rba": {"enabled": "true"}, "tags": {"type": "Anomaly", "product": "ESCU"}}, {"name": "ESCU Default Configuration Baseline", "id": "0f7ee854-1aad-4bef-89c5-5c402b488510", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type baseline.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Baseline"}}, {"name": "ESCU Default Configuration Correlation", "id": "36ba498c-46e8-4b62-8bde-67e984a40fb4", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type Correlation. These correlations will generate Notable Events.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "notable": {"rule_description": "%description%", "rule_title": "%name%", "nes_fields": []}, "tags": {"type": "Correlation", "product": "ESCU"}}, {"name": "ESCU Default Configuration Hunting", "id": "cc5895e8-3420-4ab7-af38-cf87a28f9c3b", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type hunting.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "tags": {"type": "Hunting", "product": "ESCU"}}, {"name": "ESCU Default Configuration TTP", "id": "b81cd059-a3e8-4c03-96ca-e168c50ff70b", "date": "2021-12-21", "author": "Patrick Bareiss", "description": "This configuration file applies to all detections of type TTP. These detections will use Risk Based Alerting and generate Notable Events.", "scheduling": {"cron_schedule": "0 * * * *", "earliest_time": "-70m@m", "latest_time": "-10m@m", "schedule_window": "auto"}, "notable": {"rule_description": "%description%", "rule_title": "%name%", "nes_fields": []}, "rba": {"enabled": "true"}, "tags": {"type": "TTP"}}]}
+1 -114442
View File
File diff suppressed because one or more lines are too long
+1 -353
View File
File diff suppressed because one or more lines are too long
+1 -692
View File
File diff suppressed because one or more lines are too long
+1 -1944
View File
File diff suppressed because one or more lines are too long
+1 -26514
View File
File diff suppressed because one or more lines are too long