diff --git a/detections/endpoint/7zip_commandline_to_smb_share_path.yml b/detections/endpoint/7zip_commandline_to_smb_share_path.yml index 7a6633a5b3..71a2f82616 100644 --- a/detections/endpoint/7zip_commandline_to_smb_share_path.yml +++ b/detections/endpoint/7zip_commandline_to_smb_share_path.yml @@ -44,6 +44,7 @@ tags: $dest$ mitre_attack_id: - T1560.001 + - T1560 observable: - name: dest type: Hostname diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index e696dc1e22..47edc20c3e 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -43,6 +43,7 @@ tags: Service (LSASS). mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/account_discovery_with_net_app.yml b/detections/endpoint/account_discovery_with_net_app.yml index ca323b4f37..722368e8b8 100644 --- a/detections/endpoint/account_discovery_with_net_app.yml +++ b/detections/endpoint/account_discovery_with_net_app.yml @@ -47,6 +47,7 @@ tags: message: Suspicious $process_name$ usage detected on endpoint $dest$ by user $user$. mitre_attack_id: - T1087.002 + - T1087 observable: - name: user type: User diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 11492c7e1a..e1c22878d1 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -19,9 +19,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter`' -how_to_implement: To successfully implement this search, you must be ingesting - data that records registry activity from your hosts to populate the endpoint data - model in the registry node. This is typically populated via endpoint detection-and-response +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. @@ -39,6 +39,7 @@ tags: - Exploitation mitre_attack_id: - T1547.014 + - T1547 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 9e3a41015f..45b22bb7bd 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -42,6 +42,7 @@ tags: to prepare autoadminlogon mitre_attack_id: - T1552.002 + - T1552 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index efc136fcfb..07fe3eaed1 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -38,6 +38,7 @@ tags: message: powershell process having commandline $Message$ for user enumeration mitre_attack_id: - T1087.002 + - T1087 observable: - name: ComputerName type: Hostname diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index cb0d37c557..61844a9fb4 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -36,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1562.007 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 496c7b2b3a..c82db7194b 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -42,6 +42,7 @@ tags: $dest$ by user $user$. mitre_attack_id: - T1021.001 + - T1021 observable: - name: user type: User diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 10d09995c1..644a57103f 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -38,6 +38,7 @@ tags: user $user$. mitre_attack_id: - T1021.001 + - T1021 observable: - name: user type: User diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index aedebe1507..a704470b3f 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -38,6 +38,7 @@ tags: - Exploitation mitre_attack_id: - T1562.007 + - T1562 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index b1832ffe70..a9e51c4f46 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -47,6 +47,7 @@ tags: of 7zip. mitre_attack_id: - T1560.001 + - T1560 observable: - name: user type: User diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 70f5e17175..c033e1f993 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -47,6 +47,7 @@ tags: on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadFile within PowerShell. mitre_attack_id: + - T1059 - T1059.001 observable: - name: user diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 72a6433db8..6de61407fb 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -44,6 +44,7 @@ tags: on endpoint $dest$ by user $user$. This behavior identifies the use of DownloadString within PowerShell. mitre_attack_id: + - T1059 - T1059.001 observable: - name: user diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 72e83809e5..896c3bc0cd 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -51,8 +51,9 @@ tags: on host $dest$ by User $user$. This process $process_name$ is known to do- $description$ mitre_attack_id: - T1036.005 - - T1595 + - T1036 - T1003 + - T1595 nist: - ID.AM - PR.DS diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 87a828d8d3..2d327cc01e 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -46,6 +46,7 @@ tags: attempting to add a certificate to the store on endpoint $dest$ by user $user$. mitre_attack_id: - T1553.004 + - T1553 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 8dfea2057d..1f5645aacf 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -49,6 +49,7 @@ tags: attempting to disable security services on endpoint $dest$ by user $user$. mitre_attack_id: - T1562.001 + - T1562 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index bedad02553..c3778c3143 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -47,6 +47,7 @@ tags: on endpoint $dest$ by user $user$ attempting to export the registry keys. mitre_attack_id: - T1003.002 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index 57027ab701..0ce8b228ee 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -42,6 +42,7 @@ tags: to prepare autoadminlogon mitre_attack_id: - T1552.002 + - T1552 observable: - name: dest type: Endpoint diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 85a1dab5a8..1e1cceeded 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -50,6 +50,7 @@ tags: message: A file - $file_name$ was written to system32 has occurred on endpoint $dest$ by user $user$. mitre_attack_id: + - T1204 - T1204.002 nist: - PR.PT diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index 44cab51f50..c9f9b9b0d7 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -36,6 +36,7 @@ tags: - Exploitation mitre_attack_id: - T1546.001 + - T1546 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml index 5d35b552ed..5b072f7c71 100644 --- a/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml +++ b/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml @@ -40,6 +40,7 @@ tags: of a specific disk. mitre_attack_id: - T1070.004 + - T1070 observable: - name: user type: User diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index abb7fbc623..4b39807d71 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -44,8 +44,10 @@ tags: on endpoint $dest$ by user $user$ potentially performing privilege escalation using named pipes related to Cobalt Strike and other frameworks. mitre_attack_id: + - T1059 - T1059.003 - T1543.003 + - T1543 observable: - name: user type: User diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index 5f9d81f862..67ac89ff4d 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -44,6 +44,7 @@ tags: message: parent process name $parent_process_name$ with child process $process_name$ to execute commandline tool in $dest$ mitre_attack_id: + - T1059 - T1059.007 observable: - name: dest diff --git a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml index 1761c1e1a8..c14995c3de 100644 --- a/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml +++ b/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml @@ -38,6 +38,7 @@ tags: message: The following module $ImageLoaded$ was loaded by a non-standard application on endpoint $Computer$ by user $user$. mitre_attack_id: + - T1218 - T1218.003 observable: - name: user diff --git a/detections/endpoint/control_loading_from_world_writable_directory.yml b/detections/endpoint/control_loading_from_world_writable_directory.yml index d62533f867..050e6a3f9d 100644 --- a/detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/detections/endpoint/control_loading_from_world_writable_directory.yml @@ -47,6 +47,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk. mitre_attack_id: + - T1218 - T1218.002 observable: - name: user diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index d306699d3a..5c42674597 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -46,6 +46,7 @@ tags: group. mitre_attack_id: - T1136.001 + - T1136 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index 0ceb58467d..57a2ce24f5 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -42,6 +42,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ enumerating Windows file shares. mitre_attack_id: + - T1070 - T1070.005 nist: - PR.PT diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index 57d91634f5..a14767b732 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -41,6 +41,7 @@ tags: behavior is indicative of credential dumping and should be investigated. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/create_service_in_suspicious_file_path.yml b/detections/endpoint/create_service_in_suspicious_file_path.yml index 22b3182108..fc021d10ca 100644 --- a/detections/endpoint/create_service_in_suspicious_file_path.yml +++ b/detections/endpoint/create_service_in_suspicious_file_path.yml @@ -36,6 +36,7 @@ tags: message: A service $Service_File_Name$ was created from a non-standard path using $Service_Name$, potentially leading to a privilege escalation. mitre_attack_id: + - T1569 - T1569.002 observable: - name: Service_File_Name diff --git a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml index 38e69d706d..e497bf35aa 100644 --- a/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml +++ b/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml @@ -47,6 +47,7 @@ tags: to disk. This behavior is related to dumping credentials via Task Manager. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index ffea072795..9d6834c7db 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -45,6 +45,7 @@ tags: offline password cracking. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index aa1e8a3c66..74bf3b4f5d 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -43,6 +43,7 @@ tags: offline password cracking. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 936ac84c34..85bd4e7891 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -45,6 +45,7 @@ tags: password cracking. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index 58e83ed423..9efa0420bb 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -43,6 +43,7 @@ tags: to grab credentials. mitre_attack_id: - T1003.003 + - T1003 nist: - DE.CM observable: diff --git a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml index 148c40261b..7b38c7b154 100644 --- a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml @@ -38,6 +38,7 @@ tags: message: The following $EventCode$ occurred on $dest$ by $user$ with Logon Type 3, which may be indicative of the pass the hash technique. mitre_attack_id: + - T1550 - T1550.002 nist: - PR.PT diff --git a/detections/endpoint/detect_azurehound_command_line_arguments.yml b/detections/endpoint/detect_azurehound_command_line_arguments.yml index cdffb2151f..609fee47b8 100644 --- a/detections/endpoint/detect_azurehound_command_line_arguments.yml +++ b/detections/endpoint/detect_azurehound_command_line_arguments.yml @@ -42,10 +42,12 @@ tags: on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD. mitre_attack_id: - T1087.002 - - T1087.001 - - T1482 - - T1069.002 - T1069.001 + - T1482 + - T1087.001 + - T1087 + - T1069.002 + - T1069 observable: - name: user type: User diff --git a/detections/endpoint/detect_azurehound_file_modifications.yml b/detections/endpoint/detect_azurehound_file_modifications.yml index 6537197435..3b77169959 100644 --- a/detections/endpoint/detect_azurehound_file_modifications.yml +++ b/detections/endpoint/detect_azurehound_file_modifications.yml @@ -45,10 +45,12 @@ tags: a AzureAD enumeration utility, has occurred on endpoint $dest$ by user $user$. mitre_attack_id: - T1087.002 - - T1087.001 - - T1482 - - T1069.002 - T1069.001 + - T1482 + - T1087.001 + - T1087 + - T1069.002 + - T1069 observable: - name: user type: User diff --git a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml index b95e0fedc1..d767e38a31 100644 --- a/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml +++ b/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml @@ -49,6 +49,7 @@ tags: $ComputerName$ by user $user$. mitre_attack_id: - T1003.002 + - T1003 observable: - name: user type: User diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index 8038ff0b2f..91d192b29d 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -47,6 +47,7 @@ tags: investigated. mitre_attack_id: - T1003.001 + - T1003 nist: - PR.IP - PR.AC diff --git a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml index c3984d7e63..8bb5dffc0e 100644 --- a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml @@ -51,6 +51,7 @@ tags: message: The following behavior was identified and typically related to PowerShell-Empire on $ComputerName$ by $User$. mitre_attack_id: + - T1059 - T1059.001 observable: - name: User diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index a12a7c815d..5b98774eff 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -49,6 +49,7 @@ tags: message: Multiple accounts have been locked out. Review $dest$ and results related to $user$. mitre_attack_id: + - T1078 - T1078.002 nist: - PR.IP diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index 92f0dca7aa..6f4faf640f 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -38,6 +38,7 @@ tags: message: Multiple accounts have been locked out. Review $nodename$ and $result$ related to $user$. mitre_attack_id: + - T1078 - T1078.003 nist: - PR.IP diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 74000753e6..ef48bc9c3b 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -65,6 +65,7 @@ tags: previously performed by HAFNIUM. Review further file modifications on endpoint $dest$ by user $user$. mitre_attack_id: + - T1505 - T1505.003 observable: - name: user diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/endpoint/detect_html_help_renamed.yml index f531890b16..22dce62ed2 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/endpoint/detect_html_help_renamed.yml @@ -53,6 +53,7 @@ tags: message: The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. mitre_attack_id: + - T1218 - T1218.001 nist: - PR.PT diff --git a/detections/endpoint/detect_html_help_spawn_child_process.yml b/detections/endpoint/detect_html_help_spawn_child_process.yml index 5610c65837..297d53a3ba 100644 --- a/detections/endpoint/detect_html_help_spawn_child_process.yml +++ b/detections/endpoint/detect_html_help_spawn_child_process.yml @@ -53,6 +53,7 @@ tags: on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior. mitre_attack_id: + - T1218 - T1218.001 nist: - PR.PT diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index bed3e0999b..1ee0da1045 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -57,6 +57,7 @@ tags: on endpoint $dest$ by user $user$ contacting a remote destination to potentally download a malicious payload. mitre_attack_id: + - T1218 - T1218.001 nist: - PR.PT diff --git a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml index 1ab7e62919..b339a00b1b 100644 --- a/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml +++ b/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml @@ -58,6 +58,7 @@ tags: message: $process_name$ has been identified using Infotech Storage Handlers to load a specific file within a CHM on $dest$ under user $user$. mitre_attack_id: + - T1218 - T1218.001 nist: - PR.PT diff --git a/detections/endpoint/detect_mimikatz_using_loaded_images.yml b/detections/endpoint/detect_mimikatz_using_loaded_images.yml index e523b79fbc..6617f7be17 100644 --- a/detections/endpoint/detect_mimikatz_using_loaded_images.yml +++ b/detections/endpoint/detect_mimikatz_using_loaded_images.yml @@ -48,6 +48,7 @@ tags: to credential dumping on $Computer$. Review for further details. mitre_attack_id: - T1003.001 + - T1003 nist: - DE.AE - DE.CM diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 51e322a863..aa378f0c38 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -49,6 +49,7 @@ tags: on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense evasion. mitre_attack_id: + - T1218 - T1218.005 nist: - PR.PT diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index d33e17dc56..a67750f930 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -46,6 +46,7 @@ tags: message: The following $process_name$ has been identified as renamed, spawning from $parent_process_name$. mitre_attack_id: + - T1218 - T1218.005 nist: - PR.PT diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index e55565847a..c49ff33249 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -50,6 +50,7 @@ tags: on endpoint $est$ by user $user$ attempting to access a remote destination to download an additional payload. mitre_attack_id: + - T1218 - T1218.005 nist: - PR.PT diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index ac040f36ea..e1152726bf 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -42,6 +42,7 @@ tags: behavior or not. mitre_attack_id: - T1136.001 + - T1136 nist: - PR.AC - DE.CM diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index fc7213197a..48dc4eac69 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -45,6 +45,7 @@ tags: using unquoted service paths. mitre_attack_id: - T1574.009 + - T1574 nist: - PR.PT - DE.CM diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 3ec0038961..0118aefed2 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -48,6 +48,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running prohibited applications. mitre_attack_id: + - T1059 - T1059.003 nist: - PR.PT diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 690fa3d715..6b8b7a8286 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -53,6 +53,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running the utility for possibly the first time. mitre_attack_id: + - T1021 - T1021.002 nist: - PR.PT diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index c451a22d1a..5ced5f0e85 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -50,6 +50,7 @@ tags: on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior for $parent_process_name$. mitre_attack_id: + - T1218 - T1218.009 nist: - PR.PT diff --git a/detections/endpoint/detect_regasm_with_network_connection.yml b/detections/endpoint/detect_regasm_with_network_connection.yml index 6b00c654be..bbcab20120 100644 --- a/detections/endpoint/detect_regasm_with_network_connection.yml +++ b/detections/endpoint/detect_regasm_with_network_connection.yml @@ -49,6 +49,7 @@ tags: message: An instance of $process_name$ contacting a remote destination was identified on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. mitre_attack_id: + - T1218 - T1218.009 nist: - PR.PT diff --git a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml index 719fcc2cfc..8fe4eeba6b 100644 --- a/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml +++ b/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml @@ -48,6 +48,7 @@ tags: message: The process $process_name$ was spawned by $parent_process_name$ without any command-line arguments on $dest$ by $user$. mitre_attack_id: + - T1218 - T1218.009 nist: - PR.PT diff --git a/detections/endpoint/detect_regsvcs_spawning_a_process.yml b/detections/endpoint/detect_regsvcs_spawning_a_process.yml index 353d09c90d..489c891e99 100644 --- a/detections/endpoint/detect_regsvcs_spawning_a_process.yml +++ b/detections/endpoint/detect_regsvcs_spawning_a_process.yml @@ -48,6 +48,7 @@ tags: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ typically not normal for this process. mitre_attack_id: + - T1218 - T1218.009 nist: - PR.PT diff --git a/detections/endpoint/detect_regsvcs_with_network_connection.yml b/detections/endpoint/detect_regsvcs_with_network_connection.yml index bcf8b2e515..7329369714 100644 --- a/detections/endpoint/detect_regsvcs_with_network_connection.yml +++ b/detections/endpoint/detect_regsvcs_with_network_connection.yml @@ -49,6 +49,7 @@ tags: message: An instance of $process_name$ contacting a remote destination was identified on endpoint $Computer$ by user $user$. This behavior is not normal for $process_name$. mitre_attack_id: + - T1218 - T1218.009 nist: - PR.PT