mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge pull request #1721 from splunk/CARS_UPDATE_MITRE_ID_B3
Cars update mitre id b3
This commit is contained in:
@@ -44,6 +44,7 @@ tags:
|
||||
$dest$
|
||||
mitre_attack_id:
|
||||
- T1560.001
|
||||
- T1560
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
Service (LSASS).
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
message: Suspicious $process_name$ usage detected on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -19,9 +19,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim
|
||||
Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`
|
||||
| `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter`'
|
||||
how_to_implement: To successfully implement this search, you must be ingesting
|
||||
data that records registry activity from your hosts to populate the endpoint data
|
||||
model in the registry node. This is typically populated via endpoint detection-and-response
|
||||
how_to_implement: To successfully implement this search, you must be ingesting data
|
||||
that records registry activity from your hosts to populate the endpoint data model
|
||||
in the registry node. This is typically populated via endpoint detection-and-response
|
||||
product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
|
||||
used for this search is typically generated via logs that report reads and writes
|
||||
to the registry.
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1547.014
|
||||
- T1547
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
to prepare autoadminlogon
|
||||
mitre_attack_id:
|
||||
- T1552.002
|
||||
- T1552
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
message: powershell process having commandline $Message$ for user enumeration
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087
|
||||
observable:
|
||||
- name: ComputerName
|
||||
type: Hostname
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
$dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1021.001
|
||||
- T1021
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
user $user$.
|
||||
mitre_attack_id:
|
||||
- T1021.001
|
||||
- T1021
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
of 7zip.
|
||||
mitre_attack_id:
|
||||
- T1560.001
|
||||
- T1560
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile
|
||||
within PowerShell.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.001
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadString
|
||||
within PowerShell.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.001
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -51,8 +51,9 @@ tags:
|
||||
on host $dest$ by User $user$. This process $process_name$ is known to do- $description$
|
||||
mitre_attack_id:
|
||||
- T1036.005
|
||||
- T1595
|
||||
- T1036
|
||||
- T1003
|
||||
- T1595
|
||||
nist:
|
||||
- ID.AM
|
||||
- PR.DS
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
attempting to add a certificate to the store on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1553.004
|
||||
- T1553
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
attempting to disable security services on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$ attempting to export the registry keys.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
to prepare autoadminlogon
|
||||
mitre_attack_id:
|
||||
- T1552.002
|
||||
- T1552
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
message: A file - $file_name$ was written to system32 has occurred on endpoint $dest$
|
||||
by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
- T1204.002
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1546.001
|
||||
- T1546
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
of a specific disk.
|
||||
mitre_attack_id:
|
||||
- T1070.004
|
||||
- T1070
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -44,8 +44,10 @@ tags:
|
||||
on endpoint $dest$ by user $user$ potentially performing privilege escalation
|
||||
using named pipes related to Cobalt Strike and other frameworks.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.003
|
||||
- T1543.003
|
||||
- T1543
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
message: parent process name $parent_process_name$ with child process $process_name$
|
||||
to execute commandline tool in $dest$
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.007
|
||||
observable:
|
||||
- name: dest
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
message: The following module $ImageLoaded$ was loaded by a non-standard application
|
||||
on endpoint $Computer$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.003
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.002
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
group.
|
||||
mitre_attack_id:
|
||||
- T1136.001
|
||||
- T1136
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ enumerating Windows file shares.
|
||||
mitre_attack_id:
|
||||
- T1070
|
||||
- T1070.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
behavior is indicative of credential dumping and should be investigated.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
message: A service $Service_File_Name$ was created from a non-standard path using
|
||||
$Service_Name$, potentially leading to a privilege escalation.
|
||||
mitre_attack_id:
|
||||
- T1569
|
||||
- T1569.002
|
||||
observable:
|
||||
- name: Service_File_Name
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
to disk. This behavior is related to dumping credentials via Task Manager.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
offline password cracking.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
offline password cracking.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
password cracking.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
to grab credentials.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
nist:
|
||||
- DE.CM
|
||||
observable:
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
message: The following $EventCode$ occurred on $dest$ by $user$ with Logon Type
|
||||
3, which may be indicative of the pass the hash technique.
|
||||
mitre_attack_id:
|
||||
- T1550
|
||||
- T1550.002
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -42,10 +42,12 @@ tags:
|
||||
on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD.
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087.001
|
||||
- T1482
|
||||
- T1069.002
|
||||
- T1069.001
|
||||
- T1482
|
||||
- T1087.001
|
||||
- T1087
|
||||
- T1069.002
|
||||
- T1069
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -45,10 +45,12 @@ tags:
|
||||
a AzureAD enumeration utility, has occurred on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1087.001
|
||||
- T1482
|
||||
- T1069.002
|
||||
- T1069.001
|
||||
- T1482
|
||||
- T1087.001
|
||||
- T1087
|
||||
- T1069.002
|
||||
- T1069
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
$ComputerName$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
investigated.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- PR.IP
|
||||
- PR.AC
|
||||
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
message: The following behavior was identified and typically related to PowerShell-Empire
|
||||
on $ComputerName$ by $User$.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.001
|
||||
observable:
|
||||
- name: User
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: Multiple accounts have been locked out. Review $dest$ and results related
|
||||
to $user$.
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.002
|
||||
nist:
|
||||
- PR.IP
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
message: Multiple accounts have been locked out. Review $nodename$ and $result$
|
||||
related to $user$.
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.003
|
||||
nist:
|
||||
- PR.IP
|
||||
|
||||
@@ -65,6 +65,7 @@ tags:
|
||||
previously performed by HAFNIUM. Review further file modifications on endpoint
|
||||
$dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1505
|
||||
- T1505.003
|
||||
observable:
|
||||
- name: user
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
message: The following $process_name$ has been identified as renamed, spawning from
|
||||
$parent_process_name$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$ spawning a child process, typically not normal
|
||||
behavior.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -57,6 +57,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$ contacting a remote destination to potentally
|
||||
download a malicious payload.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -58,6 +58,7 @@ tags:
|
||||
message: $process_name$ has been identified using Infotech Storage Handlers to load
|
||||
a specific file within a CHM on $dest$ under user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
to credential dumping on $Computer$. Review for further details.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
nist:
|
||||
- DE.AE
|
||||
- DE.CM
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense
|
||||
evasion.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
message: The following $process_name$ has been identified as renamed, spawning from
|
||||
$parent_process_name$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
on endpoint $est$ by user $user$ attempting to access a remote destination to
|
||||
download an additional payload.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
behavior or not.
|
||||
mitre_attack_id:
|
||||
- T1136.001
|
||||
- T1136
|
||||
nist:
|
||||
- PR.AC
|
||||
- DE.CM
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
using unquoted service paths.
|
||||
mitre_attack_id:
|
||||
- T1574.009
|
||||
- T1574
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ running prohibited applications.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.003
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -53,6 +53,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ running the utility for possibly the first time.
|
||||
mitre_attack_id:
|
||||
- T1021
|
||||
- T1021.002
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -50,6 +50,7 @@ tags:
|
||||
on endpoint $dest$ by user $user$ spawning a child process, typically not normal
|
||||
behavior for $parent_process_name$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: An instance of $process_name$ contacting a remote destination was identified
|
||||
on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
message: The process $process_name$ was spawned by $parent_process_name$ without
|
||||
any command-line arguments on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ typically not normal for this process.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: An instance of $process_name$ contacting a remote destination was identified
|
||||
on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
nist:
|
||||
- PR.PT
|
||||
|
||||
Reference in New Issue
Block a user