mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Adding old tests that point to S3 pre-parsed datasets.
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test
|
||||
tests:
|
||||
- name: Applying Stolen Credentials via Mimikatz modules
|
||||
file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml
|
||||
description: Test applying stolen credentials detections
|
||||
pass_condition: '@count_gt(0)'
|
||||
attack_data:
|
||||
- file_name: logAllMimikatzModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Applying Stolen Credentials via PowerSploit
|
||||
file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test applying stolen credentials detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction indicative of use of DSInternals credential conversion modules - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of use of DSInternals credential conversion modules
|
||||
file: endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logAllDSInternalsModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction indicative of use of DSInternals modules - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of use of DSInternals modules
|
||||
file: endpoint/ssa___credential_extraction_dsinternals_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logAllDSInternalsModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction indicative of FGDump and CacheDump with s option - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of FGDump and CacheDump with s option
|
||||
file: endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logFgdump.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logFgdump.log
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
name: Credential Extraction indicative of FGDump and CacheDump with v option - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of FGDump and CacheDump with v option
|
||||
file: endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logFgdump.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logFgdump.log
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals
|
||||
file: endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logPowerShellModule.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logPowerShellModule.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction indicative of Lazagne command line options - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of Lazagne command line options
|
||||
file: endpoint/ssa___credential_extraction_lazagne_command_options.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logLazagneCredDump.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logLazagneCredDump.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction indicative of use of Mimikatz modules - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of use of Mimikatz modules
|
||||
file: endpoint/ssa___credential_extraction_mimikatz_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logAllMimikatzModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction native Microsoft debuggers peek into the kernel - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction native Microsoft debuggers peek into the kernel
|
||||
file: endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logLiveKDFullKernelDump.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logLiveKDFullKernelDump.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction native Microsoft debuggers via z command line option - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction native Microsoft debuggers via z command line option
|
||||
file: endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logLiveKDFullKernelDump.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logLiveKDFullKernelDump.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Credential Extraction indicative of use of PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Credential Extraction indicative of use of PowerSploit modules
|
||||
file: endpoint/ssa___credential_extraction_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test credential extraction detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Illegal Access To User Content via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Access To User Content via PowerSploit modules
|
||||
file: endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal access to user content detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Illegal Account Creation via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Account Creation via PowerSploit modules
|
||||
file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal account creation detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Illegal Enabling or Disabling of Accounts via DSInternals modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Enabling or Disabling of Accounts via DSInternals modules
|
||||
file: endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test enabling or disabling of accounts detections
|
||||
attack_data:
|
||||
- file_name: logAllDSInternalsModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Illegal Deletion of Logs via Mimikatz modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Deletion of Logs via Mimikatz modules
|
||||
file: endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal log deletion detections
|
||||
attack_data:
|
||||
- file_name: logAllMimikatzModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log
|
||||
|
||||
+9
@@ -0,0 +1,9 @@
|
||||
name: Illegal Management of Active Directory Elements and Policies via DSInternals modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Management of Active Directory Elements and Policies via DSInternals modules
|
||||
file: endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal management of Active Directory elements and policies detections
|
||||
attack_data:
|
||||
- file_name: logAllDSInternalsModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
name: Illegal Management of Computers and Active Directory Elements via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Management of Computers and Active Directory Elements via PowerSploit modules
|
||||
file: endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal management of computers and Active Directory elements detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Privilege Elevation and Persistence via PowerSploit modules
|
||||
file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test privilege elevation and persistence detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Privilege Elevation via Mimikatz modules
|
||||
file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal privilege elevation detections
|
||||
attack_data:
|
||||
- file_name: logAllMimikatzModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log
|
||||
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Service and Process Control via Mimikatz modules
|
||||
file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal service and process control detections
|
||||
attack_data:
|
||||
- file_name: logAllMimikatzModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log
|
||||
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Illegal Service and Process Control via PowerSploit modules
|
||||
file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal service and process control detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Setting Credentials via DSInternals modules - SSA Unit test
|
||||
tests:
|
||||
- name: Setting Credentials via DSInternals modules
|
||||
file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal credential setting detections
|
||||
attack_data:
|
||||
- file_name: logAllDSInternalsModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Setting Credentials via Mimikatz modules - SSA Unit test
|
||||
tests:
|
||||
- name: Setting Credentials via Mimikatz modules
|
||||
file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal credential setting detections
|
||||
attack_data:
|
||||
- file_name: logAllMimikatzModules.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
name: Setting Credentials via PowerSploit modules - SSA Unit test
|
||||
tests:
|
||||
- name: Setting Credentials via PowerSploit modules
|
||||
file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml
|
||||
pass_condition: '@count_gt(0)'
|
||||
description: Test illegal credential setting detections
|
||||
attack_data:
|
||||
- file_name: logAllPowerSploitModulesWithOldNames.log
|
||||
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log
|
||||
|
||||
Reference in New Issue
Block a user