From c302325663d18fca40de5361dcde7dfce7ccb4cb Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Fri, 20 Aug 2021 11:53:42 -0600 Subject: [PATCH] Updated URLs and fixes --- .../endpoint/suspicious_microsoft_workflow_compiler_rename.yml | 2 +- .../endpoint/suspicious_microsoft_workflow_compiler_usage.yml | 2 +- detections/endpoint/suspicious_reg_exe_process.yml | 3 ++- .../suspicious_microsoft_workflow_compiler_usage.test.yml | 2 +- 4 files changed, 5 insertions(+), 4 deletions(-) diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index 80d0057183..8c1bfcbb93 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -41,7 +41,7 @@ tags: - Stage:Execution - Stage:Defense Evasion dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log impact: 70 kill_chain_phases: - Exploitation diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml index 182245810b..5bb1b0349d 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml @@ -37,7 +37,7 @@ tags: - Stage:Execution - Stage:Defense Evasion dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log impact: 70 kill_chain_phases: - Exploitation diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 95e24b7f34..4cf040bdfb 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -4,7 +4,8 @@ version: 4 date: '2020-07-22' author: David Dorsey, Splunk type: TTP -datamodel: [] +datamodel: + - Endpoint description: This search looks for reg.exe being launched from a command prompt not started by the user. When a user launches cmd.exe, the parent process is usually explorer.exe. This search filters out those instances. diff --git a/tests/endpoint/suspicious_microsoft_workflow_compiler_usage.test.yml b/tests/endpoint/suspicious_microsoft_workflow_compiler_usage.test.yml index 6593f91cb4..b81b1c6d9f 100644 --- a/tests/endpoint/suspicious_microsoft_workflow_compiler_usage.test.yml +++ b/tests/endpoint/suspicious_microsoft_workflow_compiler_usage.test.yml @@ -7,6 +7,6 @@ tests: latest_time: 'now' attack_data: - file_name: windows-sysmon.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog