From 8757c002fc5996113df990b920fb0a7df1ea217a Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Mon, 5 Jul 2021 16:45:13 +0200 Subject: [PATCH 1/6] Update allow_file_and_printing_sharing_in_firewall.yml --- .../endpoint/allow_file_and_printing_sharing_in_firewall.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 554c0b6c26..17401a0ab0 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -28,7 +28,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: From f3097ae838f60d9112ff95fe27253658416f239c Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Mon, 5 Jul 2021 16:45:31 +0200 Subject: [PATCH 2/6] Update allow_file_and_printing_sharing_in_firewall.yml --- .../endpoint/allow_file_and_printing_sharing_in_firewall.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 17401a0ab0..6931d18528 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -28,7 +28,6 @@ references: tags: analytic_story: - Ransomware - - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: From e88845c1c5bec05300e759ef9cb95a67448d4168 Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Mon, 5 Jul 2021 16:45:45 +0200 Subject: [PATCH 3/6] Update allow_network_discovery_in_firewall.yml --- detections/endpoint/allow_network_discovery_in_firewall.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index 18e94ee9e2..50bfc8ebc3 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -29,7 +29,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: From bcda9adb5609cd9d25190c9134543012ccff6848 Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Mon, 5 Jul 2021 16:46:12 +0200 Subject: [PATCH 4/6] Update disable_windows_behavior_monitoring.yml --- detections/endpoint/disable_windows_behavior_monitoring.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index a875b904e6..eb1bab4b20 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -33,7 +33,7 @@ tags: analytic_story: - Windows Defense Evasion Tactics - Ransomware - - Revil + - Revil Ransomware automated_detection_testing: passed dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log From 3e63f7325a245f4352f58cdd8b411a2ce5fe70f8 Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Mon, 5 Jul 2021 16:46:45 +0200 Subject: [PATCH 5/6] Update msmpeng_application_dll_side_loading.yml --- detections/endpoint/msmpeng_application_dll_side_loading.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index 072849d013..f27adaf028 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -26,7 +26,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: From 808eba05e497c234316e5a9e4737c6d31ad0deff Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Mon, 5 Jul 2021 16:46:58 +0200 Subject: [PATCH 6/6] Update powershell_disable_security_monitoring.yml --- detections/endpoint/powershell_disable_security_monitoring.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index 79da1e604b..3f39baed5c 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -26,7 +26,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: