mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating lookups from latest mapping
This commit is contained in:
@@ -0,0 +1,195 @@
|
||||
Name,Content Type,Deprecated in Version,Reason,Migration Guide,Replacement Content
|
||||
ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2
|
||||
ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
|
||||
ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4
|
||||
ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
|
||||
ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.
|
||||
This would ease management and false positives tuning.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
|
||||
ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5
|
||||
ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7
|
||||
ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59
|
||||
ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1
|
||||
ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
|
||||
ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde
|
||||
ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1
|
||||
ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
|
||||
ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f
|
||||
ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019
|
||||
ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c
|
||||
ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,"This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely:
|
||||
|
||||
Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277
|
||||
Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277
|
||||
ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
|
||||
ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746
|
||||
ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81
|
||||
ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8
|
||||
ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af
|
||||
ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70
|
||||
ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1
|
||||
ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
|
||||
ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31
|
||||
ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d
|
||||
ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5
|
||||
ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
|
||||
ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
|
||||
ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
|
||||
ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9
|
||||
ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359
|
||||
ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727
|
||||
ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
|
||||
ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
|
||||
ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b
|
||||
ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218
|
||||
ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71
|
||||
ESCU - Domain Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..
|
||||
It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
|
||||
ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959
|
||||
ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
|
||||
ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122
|
||||
ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d
|
||||
ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
|
||||
ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e
|
||||
ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
|
||||
ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517
|
||||
ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
|
||||
ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d
|
||||
ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75
|
||||
ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30
|
||||
ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613
|
||||
ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078
|
||||
ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45
|
||||
ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156
|
||||
ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e
|
||||
ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
|
||||
ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
|
||||
ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09
|
||||
ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a
|
||||
ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
|
||||
ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65
|
||||
ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
|
||||
ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342
|
||||
ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c
|
||||
ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf
|
||||
ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d
|
||||
ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
|
||||
ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82
|
||||
ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149
|
||||
ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393
|
||||
ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0
|
||||
ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19
|
||||
ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
|
||||
ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f
|
||||
ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f
|
||||
ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc
|
||||
ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6
|
||||
ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
|
||||
ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
|
||||
ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002
|
||||
ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73
|
||||
ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Github Commit Changes In Master - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Github Commit In Develop - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - GitHub Dependabot Alert - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Known Services Killed by Ransomware - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Suspicious Process File Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
|
||||
AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
|
||||
|
@@ -0,0 +1,9 @@
|
||||
name: deprecation_info
|
||||
date: 2025-03-14
|
||||
version: 1
|
||||
id: d83dad4f-7bce-4979-bf07-a88c610da5f6
|
||||
author: Splunk Threat Research Team
|
||||
lookup_type: csv
|
||||
default_match: false
|
||||
description: A lookup file for deprecation information
|
||||
min_matches: 1
|
||||
Reference in New Issue
Block a user