mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge remote-tracking branch 'github_origin/develop' into daftpunk
This commit is contained in:
+1
-1
@@ -1,4 +1,4 @@
|
||||
[submodule "contentctl"]
|
||||
path = contentctl
|
||||
url = https://github.com/splunk/contentctl.git
|
||||
ignore = all
|
||||
ignore = all
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
# Set a default so everything is owned by a codeowner
|
||||
* @okta-groups/sg-apps-strt-admin
|
||||
+1
-1
Submodule contentctl updated: f1a06d04ba...d9ce71bb2d
+12
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -18428,6 +18428,17 @@ searches = ["ESCU - Windows Service Created with Suspicious Service Path - Rule"
|
||||
description = The Snake implant is considered the most sophisticated cyber espionage tool designed and used by Center 16 of Russia's Federal Security Service (FSB) for long-term intelligence collection on sensitive targets.
|
||||
narrative = The Snake implant is considered the most sophisticated cyber espionage tool designed and used by Center 16 of Russia's Federal Security Service (FSB) for long-term intelligence collection on sensitive targets. To conduct operations using this tool, the FSB created a covert peer-to-peer (P2P) network of numerous Snake-infected computers worldwide. Many systems in this P2P network serve as relay nodes which route disguised operational traffic to and from Snake implants on the FSB's ultimate targets. Snake's custom communications protocols employ encryption and fragmentation for confidentiality and are designed to hamper detection and collection efforts. We consider Snake to be the most sophisticated cyber espionage tool in the FSB's arsenal. The sophistication of Snake stems from three principal areas. First, Snake employs means to achieve a rare level of stealth in its host components and network communications. Second, Snake's internal technical architecture allows for easy incorporation of new or replacement components. This design also facilitates the development and interoperability of Snake instances running on different host operating systems. We have observed interoperable Snake implants for Windows, MacOS, and Linux operating systems. Lastly, Snake demonstrates careful software engineering design and implementation, with the implant containing surprisingly few bugs given its complexity. (CISA, 2023)
|
||||
|
||||
[analytic_story://Snake Keylogger]
|
||||
category = Adversary Tactics
|
||||
last_updated = 2024-02-12
|
||||
version = 1
|
||||
references = ["https://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger", "https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-malware/snake-keylogger-malware/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect Regasm Spawning a Process - Rule", "ESCU - Download Files Using Telegram - Rule", "ESCU - Executables Or Script Creation In Suspicious Path - Rule", "ESCU - High Process Termination Frequency - Rule", "ESCU - Non Chrome Process Accessing Chrome Default Dir - Rule", "ESCU - Non Firefox Process Access Firefox Profile Dir - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious Driver Loaded Path - Rule", "ESCU - Suspicious Process DNS Query Known Abuse Web Services - Rule", "ESCU - Suspicious Process Executed From Container File - Rule", "ESCU - Windows Credentials from Password Stores Chrome LocalState Access - Rule", "ESCU - Windows Credentials from Password Stores Chrome Login Data Access - Rule", "ESCU - Windows File Transfer Protocol In Non-Common Process Path - Rule", "ESCU - Windows Gather Victim Network Info Through Ip Check Web Services - Rule", "ESCU - Windows Non Discord App Access Discord LevelDB - Rule", "ESCU - Windows Phishing PDF File Executes URL Link - Rule", "ESCU - Windows System Network Connections Discovery Netsh - Rule", "ESCU - Windows Time Based Evasion via Choice Exec - Rule", "ESCU - Windows Unsecured Outlook Credentials Access In Registry - Rule", "ESCU - Windows User Execution Malicious URL Shortcut File - Rule"]
|
||||
description = SnakeKeylogger is a stealthy malware designed to secretly record keystrokes on infected devices. It operates covertly in the background, capturing sensitive information such as passwords and credit card details. This keylogging threat poses a significant risk to user privacy and security.
|
||||
narrative = SnakeKeylogger, a notorious malware, first emerged in the early 2010s, gaining infamy for its clandestine ability to capture keystrokes on compromised systems. As a stealthy threat, it infiltrates computers silently, recording every keystroke entered by users, including sensitive information like passwords and financial details. Over time, it has evolved to evade detection mechanisms, posing a persistent threat to cybersecurity. Its widespread use in various cybercrime activities underscores its significance as a tool for espionage and data theft. Despite efforts to combat it, SnakeKeylogger continues to lurk in the shadows, perpetuating its malicious activities with devastating consequences.
|
||||
|
||||
[analytic_story://Sneaky Active Directory Persistence Tricks]
|
||||
category = Adversary Tactics
|
||||
last_updated = 2022-08-29
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -10,7 +10,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 20240306220709
|
||||
build = 20240306221540
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-03-06T22:09:27 UTC
|
||||
# On Date: 2024-03-06T22:17:33 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
@@ -1 +1 @@
|
||||
{"version": {"name": "v4.26.0", "published_at": "2024-03-06T22:13:24Z"}}
|
||||
{"version": {"name": "v4.26.0", "published_at": "2024-03-06T22:21:51Z"}}
|
||||
+176
-126
File diff suppressed because one or more lines are too long
+8
-8
@@ -1,20 +1,20 @@
|
||||
attackcti==0.3.9
|
||||
docker==6.1.3
|
||||
GitPython==3.1.37
|
||||
Jinja2==3.1.2
|
||||
jsonschema==4.19.1
|
||||
GitPython==3.1.42
|
||||
Jinja2==3.1.3
|
||||
jsonschema==4.21.1
|
||||
mock==4.0.3
|
||||
psutil==5.9.5
|
||||
psutil==5.9.8
|
||||
pycvesearch==1.2
|
||||
pydantic==1.10.8
|
||||
pysigma==0.9.8
|
||||
pysigma-backend-splunk==1.0.2
|
||||
pytest==7.4.2
|
||||
pysigma==0.11.3
|
||||
pysigma-backend-splunk==1.1.0
|
||||
pytest==7.4.4
|
||||
PyYAML>=5.4.1
|
||||
questionary==1.10.0
|
||||
requests==2.31.0
|
||||
six==1.16.0
|
||||
splunk-sdk==1.7.4
|
||||
wrapt-timeout-decorator==1.3.12.2
|
||||
wrapt-timeout-decorator==1.5.1
|
||||
xmltodict==0.13.0
|
||||
|
||||
|
||||
Reference in New Issue
Block a user