diff --git a/tests/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.test.yml b/tests/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.test.yml new file mode 100644 index 0000000000..14d0c0b8b2 --- /dev/null +++ b/tests/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.test.yml @@ -0,0 +1,10 @@ +name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test +tests: + - name: Applying Stolen Credentials via Mimikatz modules + file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml + description: Test applying stolen credentials detections + pass_condition: '@count_gt(0)' + attack_data: + - file_name: logAllMimikatzModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log + diff --git a/tests/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.test.yml b/tests/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..0320b2baae --- /dev/null +++ b/tests/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test +tests: + - name: Applying Stolen Credentials via PowerSploit + file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test applying stolen credentials detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.test.yml b/tests/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.test.yml new file mode 100644 index 0000000000..50545476f6 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction indicative of use of DSInternals credential conversion modules - SSA Unit test +tests: + - name: Credential Extraction indicative of use of DSInternals credential conversion modules + file: endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logAllDSInternalsModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log + diff --git a/tests/endpoint/ssa___credential_extraction_dsinternals_modules.test.yml b/tests/endpoint/ssa___credential_extraction_dsinternals_modules.test.yml new file mode 100644 index 0000000000..719452df65 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_dsinternals_modules.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction indicative of use of DSInternals modules - SSA Unit test +tests: + - name: Credential Extraction indicative of use of DSInternals modules + file: endpoint/ssa___credential_extraction_dsinternals_modules.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logAllDSInternalsModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log + diff --git a/tests/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.test.yml b/tests/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.test.yml new file mode 100644 index 0000000000..ce3bb8c001 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction indicative of FGDump and CacheDump with s option - SSA Unit test +tests: + - name: Credential Extraction indicative of FGDump and CacheDump with s option + file: endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logFgdump.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logFgdump.log + diff --git a/tests/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.test.yml b/tests/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.test.yml new file mode 100644 index 0000000000..dc0e53e26f --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.test.yml @@ -0,0 +1,9 @@ +name: Credential Extraction indicative of FGDump and CacheDump with v option - SSA Unit test +tests: + - name: Credential Extraction indicative of FGDump and CacheDump with v option + file: endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logFgdump.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logFgdump.log diff --git a/tests/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.test.yml b/tests/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.test.yml new file mode 100644 index 0000000000..3c173cc10f --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals - SSA Unit test +tests: + - name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals + file: endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logPowerShellModule.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logPowerShellModule.log + diff --git a/tests/endpoint/ssa___credential_extraction_lazagne_command_options.test.yml b/tests/endpoint/ssa___credential_extraction_lazagne_command_options.test.yml new file mode 100644 index 0000000000..d4c9e06189 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_lazagne_command_options.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction indicative of Lazagne command line options - SSA Unit test +tests: + - name: Credential Extraction indicative of Lazagne command line options + file: endpoint/ssa___credential_extraction_lazagne_command_options.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logLazagneCredDump.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logLazagneCredDump.log + diff --git a/tests/endpoint/ssa___credential_extraction_mimikatz_modules.test.yml b/tests/endpoint/ssa___credential_extraction_mimikatz_modules.test.yml new file mode 100644 index 0000000000..e460bc3757 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_mimikatz_modules.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction indicative of use of Mimikatz modules - SSA Unit test +tests: + - name: Credential Extraction indicative of use of Mimikatz modules + file: endpoint/ssa___credential_extraction_mimikatz_modules.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logAllMimikatzModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log + diff --git a/tests/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.test.yml b/tests/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.test.yml new file mode 100644 index 0000000000..3b1d98728d --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction native Microsoft debuggers peek into the kernel - SSA Unit test +tests: + - name: Credential Extraction native Microsoft debuggers peek into the kernel + file: endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logLiveKDFullKernelDump.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logLiveKDFullKernelDump.log + diff --git a/tests/endpoint/ssa___credential_extraction_ms_debuggers_z_option.test.yml b/tests/endpoint/ssa___credential_extraction_ms_debuggers_z_option.test.yml new file mode 100644 index 0000000000..f7d02548e6 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_ms_debuggers_z_option.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction native Microsoft debuggers via z command line option - SSA Unit test +tests: + - name: Credential Extraction native Microsoft debuggers via z command line option + file: endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logLiveKDFullKernelDump.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logLiveKDFullKernelDump.log + diff --git a/tests/endpoint/ssa___credential_extraction_powersploit_modules.test.yml b/tests/endpoint/ssa___credential_extraction_powersploit_modules.test.yml new file mode 100644 index 0000000000..c0dc7b4ab3 --- /dev/null +++ b/tests/endpoint/ssa___credential_extraction_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Credential Extraction indicative of use of PowerSploit modules - SSA Unit test +tests: + - name: Credential Extraction indicative of use of PowerSploit modules + file: endpoint/ssa___credential_extraction_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test credential extraction detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.test.yml b/tests/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..fa30ad2024 --- /dev/null +++ b/tests/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Access To User Content via PowerSploit modules - SSA Unit test +tests: + - name: Illegal Access To User Content via PowerSploit modules + file: endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal access to user content detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___illegal_account_creation_via_powersploit_modules.test.yml b/tests/endpoint/ssa___illegal_account_creation_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..72e29e3c8e --- /dev/null +++ b/tests/endpoint/ssa___illegal_account_creation_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Account Creation via PowerSploit modules - SSA Unit test +tests: + - name: Illegal Account Creation via PowerSploit modules + file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal account creation detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.test.yml b/tests/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.test.yml new file mode 100644 index 0000000000..937c8448a7 --- /dev/null +++ b/tests/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Enabling or Disabling of Accounts via DSInternals modules - SSA Unit test +tests: + - name: Illegal Enabling or Disabling of Accounts via DSInternals modules + file: endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml + pass_condition: '@count_gt(0)' + description: Test enabling or disabling of accounts detections + attack_data: + - file_name: logAllDSInternalsModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log + diff --git a/tests/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.test.yml b/tests/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.test.yml new file mode 100644 index 0000000000..7c612b8095 --- /dev/null +++ b/tests/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Deletion of Logs via Mimikatz modules - SSA Unit test +tests: + - name: Illegal Deletion of Logs via Mimikatz modules + file: endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal log deletion detections + attack_data: + - file_name: logAllMimikatzModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log + diff --git a/tests/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.test.yml b/tests/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.test.yml new file mode 100644 index 0000000000..46b465d5e4 --- /dev/null +++ b/tests/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.test.yml @@ -0,0 +1,9 @@ +name: Illegal Management of Active Directory Elements and Policies via DSInternals modules - SSA Unit test +tests: + - name: Illegal Management of Active Directory Elements and Policies via DSInternals modules + file: endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal management of Active Directory elements and policies detections + attack_data: + - file_name: logAllDSInternalsModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log diff --git a/tests/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.test.yml b/tests/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..1044d859c0 --- /dev/null +++ b/tests/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Management of Computers and Active Directory Elements via PowerSploit modules - SSA Unit test +tests: + - name: Illegal Management of Computers and Active Directory Elements via PowerSploit modules + file: endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal management of computers and Active Directory elements detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.test.yml b/tests/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..a308e881c6 --- /dev/null +++ b/tests/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA Unit test +tests: + - name: Illegal Privilege Elevation and Persistence via PowerSploit modules + file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test privilege elevation and persistence detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.test.yml b/tests/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.test.yml new file mode 100644 index 0000000000..a76d25e773 --- /dev/null +++ b/tests/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test +tests: + - name: Illegal Privilege Elevation via Mimikatz modules + file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal privilege elevation detections + attack_data: + - file_name: logAllMimikatzModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log + diff --git a/tests/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.test.yml b/tests/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.test.yml new file mode 100644 index 0000000000..928c6bbf91 --- /dev/null +++ b/tests/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test +tests: + - name: Illegal Service and Process Control via Mimikatz modules + file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal service and process control detections + attack_data: + - file_name: logAllMimikatzModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log + diff --git a/tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml b/tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..8e18aaad1f --- /dev/null +++ b/tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test +tests: + - name: Illegal Service and Process Control via PowerSploit modules + file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal service and process control detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log + diff --git a/tests/endpoint/ssa___setting_credentials_via_dsinternals_modules.test.yml b/tests/endpoint/ssa___setting_credentials_via_dsinternals_modules.test.yml new file mode 100644 index 0000000000..c152e45a64 --- /dev/null +++ b/tests/endpoint/ssa___setting_credentials_via_dsinternals_modules.test.yml @@ -0,0 +1,10 @@ +name: Setting Credentials via DSInternals modules - SSA Unit test +tests: + - name: Setting Credentials via DSInternals modules + file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal credential setting detections + attack_data: + - file_name: logAllDSInternalsModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllDSInternalsModules.log + diff --git a/tests/endpoint/ssa___setting_credentials_via_mimikatz_modules.test.yml b/tests/endpoint/ssa___setting_credentials_via_mimikatz_modules.test.yml new file mode 100644 index 0000000000..3be6db0fa2 --- /dev/null +++ b/tests/endpoint/ssa___setting_credentials_via_mimikatz_modules.test.yml @@ -0,0 +1,10 @@ +name: Setting Credentials via Mimikatz modules - SSA Unit test +tests: + - name: Setting Credentials via Mimikatz modules + file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal credential setting detections + attack_data: + - file_name: logAllMimikatzModules.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllMimikatzModules.log + diff --git a/tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml b/tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml new file mode 100644 index 0000000000..b6f2fa8a38 --- /dev/null +++ b/tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml @@ -0,0 +1,10 @@ +name: Setting Credentials via PowerSploit modules - SSA Unit test +tests: + - name: Setting Credentials via PowerSploit modules + file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml + pass_condition: '@count_gt(0)' + description: Test illegal credential setting detections + attack_data: + - file_name: logAllPowerSploitModulesWithOldNames.log + data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/logAllPowerSploitModulesWithOldNames.log +