From b6f5e6b12ff4f10265b4cc35d46a43e9e8601caf Mon Sep 17 00:00:00 2001 From: d1vious Date: Wed, 27 Oct 2021 17:00:39 -0400 Subject: [PATCH] fixed issue with ATTACK table not displaying correctly --- .../doc_detections_markdown.j2 | 18 ++++---- ...12-detect_new_login_attempts_to_routers.md | 2 - ...tect_unauthorized_assets_by_mac_address.md | 2 - ...9-15-no_windows_updates_in_a_time_frame.md | 2 - ...9-email_attachments_with_lots_of_spaces.md | 2 - ...7-09-20-large_volume_of_dns_any_queries.md | 13 ++---- ...s_scanning_for_vulnerable_jboss_servers.md | 11 ++--- ...cious_requests_to_exploit_jboss_servers.md | 2 - ...-23-monitor_web_traffic_for_brand_abuse.md | 2 - ...0-13-unusually_long_content-type_length.md | 2 - ...018-01-05-monitor_email_for_brand_abuse.md | 2 - ..._blocked_outbound_traffic_from_your_aws.md | 2 - ...6-01-detect_large_outbound_icmp_packets.md | 11 ++--- ...18-06-28-detect_s3_access_from_a_new_ip.md | 11 ++--- ...ce_created_with_previously_unseen_image.md | 2 - ...-10-23-wmi_permanent_event_subscription.md | 11 ++--- ...-10-23-wmi_temporary_event_subscription.md | 11 ++--- ...1-27-detect_spike_in_s3_bucket_deletion.md | 11 ++--- .../2018-12-03-remote_wmi_command_attempt.md | 11 ++--- .../_posts/2018-12-03-usn_journal_deletion.md | 11 ++--- .../2018-12-06-suspicious_java_classes.md | 2 - .../2018-12-14-file_with_samsam_extension.md | 2 - .../2018-12-14-samsam_test_file_write.md | 11 ++--- ...01-25-processes_tapping_keyboard_events.md | 2 - ..._servers_executing_suspicious_processes.md | 11 ++--- ...5-08-unusually_long_command_line_-_mltk.md | 2 - ...credential_dumping_through_lsass_access.md | 13 ++---- ...-03-detect_mimikatz_using_loaded_images.md | 13 ++---- ...6-access_lsass_memory_for_dump_creation.md | 13 ++---- ...9-12-06-create_remote_thread_into_lsass.md | 13 ++---- .../2019-12-10-creation_of_shadow_copy.md | 13 ++---- ...-01-22-dns_query_length_outliers_-_mltk.md | 13 ++---- ...-03-creation_of_lsass_dump_with_taskmgr.md | 13 ++---- ...20-02-07-macos_-_re-opened_applications.md | 2 - ...02-20-new_container_uploaded_to_aws_ecr.md | 11 ++--- .../2020-02-21-dump_lsass_via_comsvcs_dll.md | 13 ++---- ...20-03-16-child_processes_of_spoolsv_exe.md | 11 ++--- .../2020-03-16-detect_rare_executables.md | 2 - .../2020-03-16-process_execution_via_wmi.md | 11 ++--- .../2020-03-16-script_execution_via_wmi.md | 11 ++--- .../_posts/2020-03-16-spike_in_file_writes.md | 2 - ...n_eks_kubernetes_cluster_scan_detection.md | 11 ++--- ...mazon_eks_kubernetes_pod_scan_detection.md | 11 ++--- ...0-first_time_seen_child_process_of_zoom.md | 11 ++--- ...activity_from_previously_unseen_account.md | 2 - ...28-detect_aws_console_login_by_new_user.md | 2 - ...tes_aws_detect_suspicious_kubectl_calls.md | 2 - ...interception_by_creation_of_program_exe.md | 13 ++---- ...2020-07-06-short_lived_windows_accounts.md | 13 ++---- .../2020-07-06-windows_event_log_cleared.md | 13 ++---- ...20-07-07-remote_desktop_network_traffic.md | 13 ++---- ...20-07-08-detect_new_local_admin_account.md | 13 ++---- ...p_kubernetes_cluster_pod_scan_detection.md | 11 ++--- ...-07-21-attempt_to_stop_security_service.md | 13 ++---- ...-detect_excessive_user_account_lockouts.md | 13 ++---- .../2020-07-21-detect_outbound_smb_traffic.md | 13 ++---- ...1-detect_outlook_exe_writing_a_zip_file.md | 13 ++---- ...f_cmd_exe_to_launch_script_interpreters.md | 13 ++---- ...-21-detection_of_tools_built_by_nirsoft.md | 11 ++--- ...ritten_outside_of_the_outlook_directory.md | 13 ++---- ...rs_sending_high_volume_traffic_to_hosts.md | 13 ++---- .../2020-07-21-excessive_dns_failures.md | 13 ++---- ...first_time_seen_running_windows_service.md | 13 ++---- ...g_files_and_directories_with_attrib_exe.md | 13 ++---- ...me_of_network_traffic_from_email_server.md | 13 ++---- ...shell_process_-_execution_policy_bypass.md | 13 ++---- ...th_invalid_credentials_from_the_same_ip.md | 13 ++---- .../2020-07-21-okta_account_lockout_events.md | 13 ++---- .../2020-07-21-okta_failed_sso_attempts.md | 13 ++---- ...1-okta_user_logins_from_multiple_cities.md | 13 ++---- ...7-21-overwriting_accessibility_binaries.md | 13 ++---- ...7-21-prohibited_network_traffic_allowed.md | 11 ++--- .../2020-07-21-protocol_or_port_mismatch.md | 13 ++---- ...07-21-remote_desktop_network_bruteforce.md | 13 ++---- ...emote_desktop_process_running_on_system.md | 13 ++---- ...21-sc_exe_manipulating_windows_services.md | 13 ++---- ...chtasks_scheduling_job_on_remote_system.md | 13 ++---- ...2020-07-21-sql_injection_with_long_urls.md | 11 ++--- docs/_posts/2020-07-22-smb_traffic_spike.md | 13 ++---- .../2020-07-22-smb_traffic_spike_-_mltk.md | 13 ++---- ...-suspicious_email_attachment_extensions.md | 13 ++---- .../2020-07-22-suspicious_reg_exe_process.md | 11 ++--- ...uspicious_writes_to_windows_recycle_bin.md | 11 ++--- docs/_posts/2020-07-22-tor_traffic.md | 13 ++---- .../2020-07-22-unload_sysmon_filter_driver.md | 13 ++---- ...-07-27-aws_detect_attach_to_role_policy.md | 11 ++--- ...07-27-aws_detect_permanent_key_creation.md | 11 ++--- .../2020-07-27-aws_detect_role_creation.md | 11 ++--- ...-07-27-aws_detect_sts_assume_role_abuse.md | 11 ++--- ...-aws_detect_sts_get_session_token_abuse.md | 11 ++--- ...ct_windows_dns_sigred_via_splunk_stream.md | 11 ++--- ...7-28-detect_windows_dns_sigred_via_zeek.md | 11 ++--- ...ance_modified_by_previously_unseen_user.md | 13 ++---- ...-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 11 ++--- ...-05-detect_new_open_gcp_storage_buckets.md | 11 ++--- ...detect_gcp_storage_access_from_a_new_ip.md | 11 ++--- .../_posts/2020-08-11-detect_arp_poisoning.md | 19 ++------- .../2020-08-11-detect_rogue_dhcp_server.md | 17 ++------ ...ivity_from_previously_unseen_ip_address.md | 11 ++--- ..._activity_from_previously_unseen_region.md | 11 ++--- ...igh_number_of_cloud_instances_destroyed.md | 13 ++---- ...high_number_of_cloud_instances_launched.md | 13 ++---- ...olbas_applications_in_short_time_period.md | 14 ++----- ...ection_by_machine_learning_method_-_ssa.md | 11 ++--- ...rocess_running_from_unexpected_location.md | 11 ++--- ...nce_created_in_previously_unused_region.md | 11 ++--- ...calls_from_previously_unseen_user_roles.md | 11 ++--- ...umber_of_cloud_infrastructure_api_calls.md | 13 ++---- ...umber_of_cloud_security_group_api_calls.md | 13 ++---- ...ed_with_previously_unseen_instance_type.md | 2 - ...-detect_dump_lsass_memory_using_comsvcs.md | 13 ++---- .../2020-09-15-detect_zerologon_via_zeek.md | 11 ++--- ..._or_delete_windows_shares_using_net_exe.md | 13 ++---- ...computer_changed_with_anonymous_account.md | 11 ++--- .../2020-10-06-unusually_long_command_line.md | 2 - ...aws_console_login_by_user_from_new_city.md | 11 ++--- ..._console_login_by_user_from_new_country.md | 11 ++--- ...s_console_login_by_user_from_new_region.md | 11 ++--- ...2020-10-08-gcp_detect_gcploit_framework.md | 11 ++--- ...ng_activity_from_previously_unseen_city.md | 11 ++--- ...activity_from_previously_unseen_country.md | 11 ++--- ...tivity_related_to_pass_the_hash_attacks.md | 13 ++---- ...oasting_spn_request_with_rc4_encryption.md | 13 ++---- ...e_of_fgdump_and_cachedump_with_s_option.md | 11 ++--- ...e_of_fgdump_and_cachedump_with_v_option.md | 11 ++--- ...icative_of_lazagne_command_line_options.md | 14 ++----- ...icrosoft_debuggers_peek_into_the_kernel.md | 11 ++--- ...oft_debuggers_via_z_command_line_option.md | 11 ++--- ..._present_in_powersploit_and_dsinternals.md | 11 ++--- ...internals_credential_conversion_modules.md | 11 ++--- ...ndicative_of_use_of_dsinternals_modules.md | 11 ++--- ...n_indicative_of_use_of_mimikatz_modules.md | 11 ++--- ...ndicative_of_use_of_powersploit_modules.md | 11 ++--- .../_posts/2020-10-21-detect_kerberoasting.md | 13 ++---- .../_posts/2020-10-21-detect_pass_the_hash.md | 13 ++---- ...20-10-21-detect_snicat_sni_exfiltration.md | 11 ++--- ...ect_ipv6_network_infrastructure_threats.md | 19 ++------- ...20-10-28-detect_port_security_violation.md | 19 ++------- ...ect_software_download_to_network_device.md | 13 ++---- .../2020-10-28-detect_traffic_mirroring.md | 19 ++------- ...stolen_credentials_via_mimikatz_modules.md | 41 ++----------------- ...len_credentials_via_powersploit_modules.md | 41 ++----------------- ...ential_strength_via_dsinternals_modules.md | 26 ++---------- ...tores_and_services_via_mimikatz_modules.md | 29 ++----------- ...ing_credentials_via_dsinternals_modules.md | 17 ++------ ...etting_credentials_via_mimikatz_modules.md | 17 ++------ ...ing_credentials_via_powersploit_modules.md | 17 ++------ ...len_credentials_via_powersploit_modules.md | 14 ++----- ...ccounts_and_groups_via_mimikatz_modules.md | 17 ++------ ...ps_and_policies_via_powersploit_modules.md | 17 ++------ ...e_opportunities_via_powersploit_modules.md | 26 ++---------- ...defensive_tools_via_powersploit_modules.md | 18 ++------ ...n_opportunities_via_powersploit_modules.md | 17 ++------ ...king_opportunities_via_mimikatz_modules.md | 17 ++------ ..._infrastructure_via_powersploit_modules.md | 23 ++--------- ...ers_and_domains_via_powersploit_modules.md | 17 ++------ ...ccess_to_computers_via_mimikatz_modules.md | 11 ++--- ...system_elements_via_powersploit_modules.md | 34 ++------------- ...esses_and_services_via_mimikatz_modules.md | 17 ++------ ...o_shared_resources_via_mimikatz_modules.md | 19 ++------- ...hared_resources_via_powersploit_modules.md | 19 ++------- ...of_connectivity_via_powersploit_modules.md | 19 ++------- .../2020-11-06-ryuk_test_files_detected.md | 11 ++--- ...cution_policy_to_unrestricted_or_bypass.md | 13 ++---- ...indows_security_account_manager_stopped.md | 11 ++--- ...2020-11-09-common_ransomware_extensions.md | 11 ++--- .../2020-11-09-common_ransomware_notes.md | 11 ++--- .../2020-11-09-deleting_shadow_copies.md | 11 ++--- ...xcessive_account_lockouts_from_endpoint.md | 13 ++---- ...to_user_content_via_powersploit_modules.md | 20 ++------- ...ccount_creation_via_powersploit_modules.md | 11 ++--- ...l_deletion_of_logs_via_mimikatz_modules.md | 11 ++--- ...ing_of_accounts_via_dsinternals_modules.md | 14 ++----- ...ts_and_policies_via_dsinternals_modules.md | 17 ++------ ...ectory_elements_via_powersploit_modules.md | 17 ++------ ...and_persistence_via_powersploit_modules.md | 17 ++------ ...rivilege_elevation_via_mimikatz_modules.md | 14 ++----- ...nd_process_control_via_mimikatz_modules.md | 17 ++------ ...process_control_via_powersploit_modules.md | 17 ++------ ..._system_network_configuration_discovery.md | 11 ++--- ...rohibited_applications_spawning_cmd_exe.md | 13 ++---- ...8-disabling_remote_user_account_control.md | 13 ++---- ...cution_of_file_with_multiple_extensions.md | 13 ++---- ...onitor_registry_keys_for_print_monitors.md | 13 ++---- ...installation_with_suspicious_parameters.md | 13 ++---- ...pulating_windows_services_registry_keys.md | 13 ++---- ...gistry_keys_for_creating_shim_databases.md | 13 ++---- ...stry_keys_used_for_privilege_escalation.md | 13 ++---- ...30-remote_process_instantiation_via_wmi.md | 11 ++--- ...020-11-30-rundll_loading_dll_by_ordinal.md | 13 ++---- ...2-07-schtasks_used_for_forcing_a_reboot.md | 13 ++---- .../2020-12-08-shim_database_file_creation.md | 13 ++---- ...12-08-single_letter_process_on_endpoint.md | 13 ++---- ...processes_run_from_unexpected_locations.md | 13 ++---- .../2020-12-08-unusually_long_command_line.md | 2 - ...i_permanent_event_subscription_-_sysmon.md | 13 ++---- ...burst_correlation_dll_and_network_event.md | 11 ++--- ...12-15-o365_suspicious_rights_delegation.md | 13 ++---- ..._of_login_failures_from_a_single_source.md | 13 ++---- docs/_posts/2020-12-16-o365_disable_mfa.md | 11 ++--- ...excessive_authentication_failures_alert.md | 11 ++--- .../2020-12-16-o365_pst_export_alert.md | 11 ++--- ...-o365_suspicious_admin_email_forwarding.md | 13 ++---- ...6-o365_suspicious_user_email_forwarding.md | 13 ++---- docs/_posts/2020-12-16-windows_adfind_exe.md | 11 ++--- ...heduled_task_deleted_or_created_via_cmd.md | 13 ++---- ...1-bcdedit_failure_recovery_modification.md | 11 ++--- ...edential_dump_from_registry_via_reg_exe.md | 11 ++--- ...rohibited_applications_spawning_cmd_exe.md | 11 ++--- docs/_posts/2021-01-06-supernova_webshell.md | 10 ++--- ...ng_keys_with_encrypt_policy_without_mfa.md | 11 ++--- ..._with_kms_keys_performing_encryption_s3.md | 11 ++--- ...ontrol_list_created_with_all_open_ports.md | 13 ++---- ...aws_network_access_control_list_deleted.md | 13 ++---- ...cious_microsoft_workflow_compiler_usage.md | 11 ++--- .../2021-01-12-suspicious_msbuild_path.md | 18 ++------ .../2021-01-12-suspicious_msbuild_rename.md | 18 ++------ .../2021-01-12-suspicious_msbuild_spawn.md | 13 ++---- ...21-01-12-suspicious_mshta_child_process.md | 13 ++---- ..._connecting_to_dynamic_domain_providers.md | 11 ++--- ...ell_process_with_obfuscation_techniques.md | 13 ++---- ...20-detect_rundll32_inline_hta_execution.md | 13 ++---- .../2021-01-20-suspicious_mshta_spawn.md | 13 ++---- ...021-01-22-wbadmin_delete_system_backups.md | 11 ++--- ...021-01-25-nltest_domain_trust_discovery.md | 11 ++--- ...l_access_by_provider_user_and_principal.md | 11 ++--- ...01-26-aws_saml_update_identity_provider.md | 11 ++--- ...-26-certutil_exe_certificate_extraction.md | 2 - ...ws_security_hub_alerts_for_ec2_instance.md | 2 - ...ike_in_aws_security_hub_alerts_for_user.md | 2 - ...o365_add_app_role_assignment_grant_user.md | 13 ++---- ...2021-01-26-o365_added_service_principal.md | 13 ++---- ...1-01-26-o365_excessive_sso_logon_errors.md | 11 ++--- ...1-01-26-o365_new_federated_domain_added.md | 13 ++---- ...1-27-detect_baron_samedit_cve-2021-3156.md | 11 ++--- ...baron_samedit_cve-2021-3156_via_osquery.md | 11 ++--- ...ect_regsvr32_application_control_bypass.md | 13 ++---- .../_posts/2021-01-28-ntdsutil_export_ntds.md | 13 ++---- ...cious_regsvr32_register_suspicious_path.md | 13 ++---- ...ct_baron_samedit_cve-2021-3156_segfault.md | 11 ++--- ...32_application_control_bypass_-_advpack.md | 13 ++---- ...2_application_control_bypass_-_setupapi.md | 13 ++---- ...2_application_control_bypass_-_syssetup.md | 13 ++---- .../2021-02-04-suspicious_rundll32_rename.md | 18 ++------ .../2021-02-04-suspicious_rundll32_startw.md | 13 ++---- ...9-suspicious_rundll32_dllregisterserver.md | 13 ++---- ...11-detect_html_help_spawn_child_process.md | 13 ++---- ...-02-12-detect_regasm_spawning_a_process.md | 13 ++---- ...02-12-detect_regsvcs_spawning_a_process.md | 13 ++---- ...6-detect_regasm_with_network_connection.md | 13 ++---- ...-detect_regsvcs_with_network_connection.md | 13 ++---- ...e_policy_version_to_allow_all_resources.md | 13 ++---- .../2021-02-22-cobalt_strike_named_pipes.md | 11 ++--- ...2-22-suspicious_curl_network_connection.md | 11 ++--- .../2021-02-22-suspicious_plistbuddy_usage.md | 13 ++---- ...suspicious_plistbuddy_usage_via_osquery.md | 13 ++---- ...uspicious_sqlite3_lsquarantine_behavior.md | 11 ++--- .../2021-03-01-any_powershell_downloadfile.md | 13 ++---- ...021-03-01-any_powershell_downloadstring.md | 13 ++---- docs/_posts/2021-03-01-eventvwr_uac_bypass.md | 13 ++---- .../_posts/2021-03-01-fodhelper_uac_bypass.md | 16 ++------ .../2021-03-01-ryuk_wake_on_lan_command.md | 13 ++---- ...us_scheduled_task_from_public_directory.md | 13 ++---- .../2021-03-02-aws_setdefaultpolicyversion.md | 13 ++---- ...ed_messaging_service_spawning_a_process.md | 11 ++--- ...-02-windows_disableantispyware_registry.md | 13 ++---- ...2021-03-03-nishang_powershelltcponeline.md | 13 ++---- docs/_posts/2021-03-03-w3wp_spawning_shell.md | 13 ++---- ...-create_service_in_suspicious_file_path.md | 13 ++---- ...21-03-12-ransomware_notes_bulk_creation.md | 11 ++--- .../2021-03-12-resize_shadowstorage_volume.md | 11 ++--- ...2021-03-16-high_file_deletion_frequency.md | 11 ++--- ...3-16-high_process_termination_frequency.md | 11 ++--- .../2021-03-17-clop_common_exec_parameter.md | 11 ++--- ...3-17-clop_ransomware_known_service_name.md | 11 ++--- ...-process_deleting_its_process_file_path.md | 11 ++--- ...nload_with_urlcache_and_split_arguments.md | 11 ++--- ...load_with_verifyctl_and_split_arguments.md | 11 ++--- ...021-03-23-certutil_with_decode_argument.md | 11 ++--- ...021-03-29-powershell_start-bitstransfer.md | 11 ++--- ...03-31-aws_iam_successful_group_deletion.md | 16 ++------ .../2021-03-31-disable_registry_tool.md | 13 ++---- .../2021-03-31-disable_show_hidden_files.md | 18 ++------ ...-31-disable_windows_behavior_monitoring.md | 13 ++---- ...-disable_windows_smartscreen_protection.md | 13 ++---- .../2021-03-31-disabling_cmd_application.md | 13 ++---- .../2021-03-31-disabling_controlpanel.md | 13 ++---- ...021-03-31-disabling_firewall_with_netsh.md | 13 ++---- ...disabling_folderoptions_windows_feature.md | 13 ++---- .../2021-03-31-disabling_norun_windows_app.md | 13 ++---- ...-31-disabling_systemrestore_in_registry.md | 13 ++---- .../2021-03-31-disabling_task_manager.md | 13 ++---- .../2021-03-31-dsquery_domain_discovery.md | 11 ++--- ...-aws_iam_assume_role_policy_brute_force.md | 14 ++----- .../2021-04-01-aws_iam_delete_policy.md | 11 ++--- ...21-04-01-aws_iam_failure_group_deletion.md | 11 ++--- ...5-aws_iam_accessdenied_discovery_events.md | 11 ++--- ...icious_powershell_executed_as_a_service.md | 13 ++---- ...o_authenticate_from_host_using_kerberos.md | 13 ++---- ...heduled_task_created_within_public_path.md | 13 ++---- .../2021-04-12-excel_spawning_powershell.md | 13 ++---- ...4-12-excel_spawning_windows_script_host.md | 13 ++---- ...t_scheduled_task_created_to_spawn_shell.md | 13 ++---- .../2021-04-12-winword_spawning_powershell.md | 13 ++---- ...12-winword_spawning_windows_script_host.md | 13 ++---- ...1-04-13-aws_excessive_security_scanning.md | 11 ++--- ...authenticate_using_explicit_credentials.md | 13 ++---- ...ng_to_authenticate_from_host_using_ntlm.md | 13 ++---- ...rs_failing_to_authenticate_from_process.md | 13 ++---- ...otely_failing_to_authenticate_from_host.md | 13 ++---- ...fice_application_spawn_rundll32_process.md | 13 ++---- ...o_authenticate_from_host_using_kerberos.md | 13 ++---- ...o_authenticate_from_host_using_kerberos.md | 13 ++---- ...-office_document_creating_schedule_task.md | 13 ++---- ...14-office_document_executing_macro_code.md | 13 ++---- ...-15-dns_exfiltration_using_nslookup_app.md | 11 ++--- ...ng_to_authenticate_from_host_using_ntlm.md | 13 ++---- ..._no_command_line_arguments_with_network.md | 11 ++--- ..._remote_thread_to_known_windows_process.md | 11 ++--- ...hedule_task_with_http_command_arguments.md | 11 ++--- ...dule_task_with_rundll32_command_trigger.md | 11 ++--- ...ess_connecting_to_ip_check_web_services.md | 13 ++---- ...9-wermgr_process_create_executable_file.md | 11 ++--- ...ocess_spawned_cmd_or_powershell_process.md | 11 ++--- ...1-04-21-excessive_usage_of_nslookup_app.md | 11 ++--- ...ultiple_archive_files_http_post_traffic.md | 13 ++---- .../2021-04-22-anomalous_usage_of_7zip.md | 13 ++---- ...e_product_spawning_rundll32_with_no_dll.md | 13 ++---- ...-04-22-plain_http_post_exfiltrated_data.md | 13 ++---- .../_posts/2021-04-22-winword_spawning_cmd.md | 13 ++---- ...021-04-23-write_executable_in_smb_share.md | 13 ++---- ...04-26-office_product_spawning_bitsadmin.md | 13 ++---- ...-04-26-office_product_spawning_certutil.md | 13 ++---- ...021-04-26-office_product_spawning_mshta.md | 13 ++---- docs/_posts/2021-04-26-trickbot_named_pipe.md | 11 ++--- docs/_posts/2021-04-29-icacls_deny_command.md | 11 ++--- ...021-04-29-suspicious_driver_loaded_path.md | 13 ++---- docs/_posts/2021-04-29-xmrig_driver_loaded.md | 13 ++---- .../2021-05-04-deleting_of_net_users.md | 11 ++--- .../2021-05-04-disabling_net_user_account.md | 11 ++--- ...4-excessive_attempt_to_disable_services.md | 11 ++--- ...21-05-04-excessive_service_stop_attempt.md | 11 ++--- .../2021-05-04-excessive_usage_of_taskkill.md | 13 ++---- .../_posts/2021-05-04-icacls_grant_command.md | 11 ++--- ...odify_acl_permission_to_files_or_folder.md | 11 ++--- ...21-05-04-process_kill_base_on_file_path.md | 13 ++---- .../2021-05-05-disable_windows_app_hotkeys.md | 13 ++---- ...5-hide_user_account_from_sign-in_screen.md | 13 ++---- ...2021-05-05-suspicious_process_file_path.md | 11 ++--- ...021-05-06-download_files_using_telegram.md | 11 ++--- ...merate_users_local_group_using_telegram.md | 11 ++--- .../2021-05-06-excessive_usage_of_net_app.md | 11 ++--- ...s_or_script_creation_in_suspicious_path.md | 11 ++--- ...2021-05-07-excessive_usage_of_cacls_app.md | 11 ++--- .../2021-05-07-schtasks_run_task_on_demand.md | 11 ++--- ...05-12-delete_shadowcopy_with_powershell.md | 11 ++--- ...2021-05-13-cmlua_or_cmstplua_uac_bypass.md | 13 ++---- ...-05-13-detect_rclone_command-line_usage.md | 11 ++--- docs/_posts/2021-05-13-slui_runas_elevated.md | 13 ++---- .../2021-05-13-slui_spawning_a_process.md | 13 ++---- .../2021-05-18-services_escalate_exe.md | 11 ++--- ...-allow_inbound_traffic_in_firewall_rule.md | 13 ++---- ...1-05-19-enable_rdp_in_other_port_number.md | 11 ++--- .../2021-05-19-mailsniper_invoke_functions.md | 13 ++---- .../2021-05-20-cmd_echo_pipe_-_escalation.md | 18 ++------ ...-rare_parent-child_process_relationship.md | 20 ++------- .../2021-05-21-winrm_spawning_a_process.md | 11 ++--- ...bound_traffic_by_firewall_rule_registry.md | 13 ++---- ...6-secretdumps_offline_ntds_dumping_tool.md | 13 ++---- ...27-detect_sharphound_file_modifications.md | 25 ++--------- .../2021-05-27-detect_sharphound_usage.md | 25 ++--------- ...etect_azurehound_command-line_arguments.md | 25 ++--------- ...01-detect_azurehound_file_modifications.md | 25 ++--------- ...etect_sharphound_command-line_arguments.md | 25 ++--------- .../2021-06-02-conti_common_exec_parameter.md | 11 ++--- .../2021-06-02-modification_of_wallpaper.md | 11 ++--- .../2021-06-02-revil_common_exec_parameter.md | 11 ++--- .../_posts/2021-06-02-revil_registry_entry.md | 11 ++--- ...021-06-02-wbemprox_com_object_execution.md | 13 ++---- ...rocesses_created_in_windows_temp_folder.md | 11 ++--- ...-04-known_services_killed_by_ransomware.md | 11 ++--- ...-excessive_number_of_taskhost_processes.md | 11 ++--- ...ss_process_injection_via_getprocaddress.md | 16 ++------ ..._script_contains_base64_encoded_content.md | 16 ++------ ...re_with_powershell_script_block_logging.md | 13 ++---- ...tz_with_powershell_script_block_logging.md | 11 ++--- ...021-06-09-unloading_amsi_via_reflection.md | 11 ++--- ...6-10-allow_operation_with_consent_admin.md | 11 ++--- ...ear_unallocated_sector_using_cipher_app.md | 13 ++---- .../2021-06-10-disable_logs_using_wevtutil.md | 13 ++---- ...rmission_modification_using_takeown_app.md | 11 ++--- ...-06-10-powershell_creating_thread_mutex.md | 13 ++---- ...021-06-10-powershell_domain_enumeration.md | 13 ++---- ...o_memory_via_system_reflection_assembly.md | 13 ++---- ...10-powershell_processing_stream_of_data.md | 13 ++---- ...owershell_using_memory_as_backing_store.md | 11 ++--- ...ent_automatic_repair_mode_using_bcdedit.md | 11 ++--- ...6-10-recon_avproduct_through_pwh_or_wmi.md | 11 ++--- .../2021-06-10-recon_using_wmi_class.md | 11 ++--- ...21-06-10-start_up_during_safe_mode_boot.md | 13 ++---- ...-14-deny_permission_using_cacls_utility.md | 11 ++--- ...14-grant_permission_using_cacls_utility.md | 11 ++--- ...4-wmi_recon_running_process_or_services.md | 11 ++--- ...ify_acls_permission_of_files_or_folders.md | 11 ++--- ...2021-06-15-wevtutil_usage_to_clear_logs.md | 13 ++---- ...21-06-15-wevtutil_usage_to_disable_logs.md | 13 ++---- ...tect_wmi_event_subscription_persistence.md | 13 ++---- ...7-suspicious_event_log_service_behavior.md | 13 ++---- .../2021-06-18-attempt_to_delete_services.md | 11 ++--- .../2021-06-18-attempt_to_disable_services.md | 11 ++--- .../2021-06-21-attacker_tools_on_endpoint.md | 19 ++------- docs/_posts/2021-06-21-delete_a_net_user.md | 11 ++--- .../2021-06-21-disable_net_user_account.md | 11 ++--- .../2021-06-21-resize_shadowstorage_volume.md | 11 ++--- ...021-06-22-disable_amsi_through_registry.md | 13 ++---- ...2021-06-22-disable_etw_through_registry.md | 13 ++---- ...ecute_javascript_with_jscript_com_clsid.md | 13 ++---- ...-powershell_enable_smb1protocol_feature.md | 13 ++---- ...ursive_delete_of_directory_in_batch_cmd.md | 13 ++---- ...w_file_and_printing_sharing_in_firewall.md | 13 ++---- ...-23-allow_network_discovery_in_firewall.md | 13 ++---- ...4-excessive_usage_of_sc_service_utility.md | 13 ++---- ...er_of_service_control_start_as_disabled.md | 13 ++---- ...1-print_spooler_adding_a_printer_driver.md | 13 ++---- ...-print_spooler_failed_to_load_a_plug-in.md | 13 ++---- docs/_posts/2021-07-01-sdclt_uac_bypass.md | 13 ++---- .../2021-07-01-silentcleanup_uac_bypass.md | 13 ++---- .../2021-07-01-spoolsv_spawning_rundll32.md | 13 ++---- ...07-01-spoolsv_suspicious_loaded_modules.md | 13 ++---- ...07-01-spoolsv_suspicious_process_access.md | 11 ++--- .../2021-07-01-spoolsv_writing_a_dll.md | 13 ++---- ...21-07-01-spoolsv_writing_a_dll_-_sysmon.md | 13 ++---- docs/_posts/2021-07-01-wsreset_uac_bypass.md | 13 ++---- ...05-msmpeng_application_dll_side_loading.md | 13 ++---- ...-powershell_disable_security_monitoring.md | 13 ++---- .../2021-07-12-net_profiler_uac_bypass.md | 13 ++---- ...-07-12-uac_bypass_mmc_load_unsigned_dll.md | 13 ++---- ...tance_created_by_previously_unseen_user.md | 13 ++---- docs/_posts/2021-07-19-aws_createaccesskey.md | 13 ++---- .../2021-07-19-aws_createloginprofile.md | 13 ++---- .../2021-07-19-aws_updateloginprofile.md | 13 ++---- .../2021-07-19-detect_new_open_s3_buckets.md | 11 ++--- ...detect_new_open_s3_buckets_over_aws_cli.md | 11 ++--- ...a_spawning_rundll32_or_regsvr32_process.md | 13 ++---- ...21-07-19-o365_bypass_mfa_via_trusted_ip.md | 13 ++---- ...-07-19-office_product_spawn_cmd_process.md | 13 ++---- .../2021-07-20-detect_shared_ec2_snapshot.md | 11 ++--- ...of_shadowcopy_with_script_block_logging.md | 13 ++---- ...-07-23-sam_database_file_access_attempt.md | 13 ++---- ...-rundll32_createremotethread_in_browser.md | 11 ++--- docs/_posts/2021-07-26-rundll32_dnsquery.md | 13 ++---- ...rundll32_process_creating_exe_dll_files.md | 13 ++---- ...7-26-suspicious_icedid_rundll32_cmdline.md | 13 ++---- ...21-07-26-suspicious_rundll32_plugininit.md | 13 ++---- .../2021-07-27-chcp_command_execution.md | 11 ++--- ...7-27-suspicious_icedid_regsvr32_cmdline.md | 13 ++---- ...dll32_create_remote_thread_to_a_process.md | 11 ++--- .../2021-07-30-drop_icedid_license_dat.md | 13 ++---- ...edid_exfiltrated_archived_file_creation.md | 13 ++---- ...fice_application_spawn_regsvr32_process.md | 13 ++---- ...2021-08-03-sqlite_module_in_temp_folder.md | 11 ++--- ...eate_remote_thread_in_shell_application.md | 11 ++--- .../2021-08-09-uninstall_app_using_msiexec.md | 13 ++---- ...021-08-10-powershell_execute_com_object.md | 13 ++---- docs/_posts/2021-08-11-fsutil_zeroing_file.md | 11 ++--- ...8-13-uac_bypass_with_colorui_com_object.md | 13 ++---- ...16-gsuite_drive_share_in_external_email.md | 13 ++---- ...8-16-gsuite_email_suspicious_attachment.md | 13 ++---- ...8-17-7zip_commandline_to_smb_share_path.md | 13 ++---- ...ws_ecr_container_scanning_findings_high.md | 13 ++---- ...ning_findings_low_informational_unknown.md | 13 ++---- ..._ecr_container_scanning_findings_medium.md | 13 ++---- ...mail_with_attachment_to_external_domain.md | 13 ++---- docs/_posts/2021-08-18-esentutl_sam_copy.md | 13 ++---- .../2021-08-18-powershell_4104_hunting.md | 13 ++---- ...container_upload_outside_business_hours.md | 13 ++---- ...9-aws_ecr_container_upload_unknown_user.md | 13 ++---- ...mail_suspicious_subject_with_attachment.md | 13 ++---- ...ols_passing_authentication_in_cleartext.md | 2 - ...1-08-20-github_commit_changes_in_master.md | 11 ++--- ...2021-08-20-kubernetes_nginx_ingress_lfi.md | 11 ++--- ...2021-08-23-getlocaluser_with_powershell.md | 13 ++---- ...tlocaluser_with_powershell_script_block.md | 13 ++---- ...twmiobject_user_account_with_powershell.md | 13 ++---- ...er_account_with_powershell_script_block.md | 13 ++---- ...email_with_known_abuse_web_service_link.md | 13 ++---- ...8-23-gsuite_suspicious_shared_file_name.md | 13 ++---- ...2021-08-23-kubernetes_nginx_ingress_rfi.md | 11 ++--- ...21-08-24-adsisearcher_account_discovery.md | 13 ++---- ...4-domain_account_discovery_with_dsquery.md | 13 ++---- ...4-domain_account_discovery_with_net_app.md | 13 ++---- ...8-24-domain_account_discovery_with_wmic.md | 13 ++---- ...1-08-24-get-domaintrust_with_powershell.md | 11 ++--- ...omaintrust_with_powershell_script_block.md | 11 ++--- .../2021-08-24-get_aduser_with_powershell.md | 13 ++---- ...get_aduser_with_powershell_script_block.md | 13 ++---- ...21-08-24-get_domainuser_with_powershell.md | 13 ++---- ...domainuser_with_powershell_script_block.md | 13 ++---- ...24-getwmiobject_ds_user_with_powershell.md | 13 ++---- ...ct_ds_user_with_powershell_script_block.md | 13 ++---- ...-08-24-kubernetes_scanner_image_pulling.md | 11 ++--- ...omain_group_discovery_with_adsisearcher.md | 13 ++---- ...1-08-25-domain_group_discovery_with_net.md | 13 ++---- ...-08-25-domain_group_discovery_with_wmic.md | 13 ++---- ...08-25-elevated_group_discovery_with_net.md | 13 ++---- ...elevated_group_discovery_with_powerview.md | 13 ++---- ...8-25-elevated_group_discovery_with_wmic.md | 13 ++---- .../2021-08-25-getadgroup_with_powershell.md | 13 ++---- ...getadgroup_with_powershell_script_block.md | 13 ++---- ...21-08-25-getdomaingroup_with_powershell.md | 13 ++---- ...-25-getnettcpconnection_with_powershell.md | 11 ++--- ...5-getwmiobject_ds_group_with_powershell.md | 13 ++---- ...t_ds_group_with_powershell_script_block.md | 13 ++---- ...ultdomainpasswordpolicy_with_powershell.md | 11 ++--- ...wordpolicy_with_powershell_script_block.md | 11 ++--- ...resultantpasswordpolicy_with_powershell.md | 11 ++--- ...wordpolicy_with_powershell_script_block.md | 11 ++--- ...-08-26-get_domainpolicy_with_powershell.md | 11 ++--- ...mainpolicy_with_powershell_script_block.md | 11 ++--- ...omaingroup_with_powershell_script_block.md | 13 ++---- ...8-26-password_policy_discovery_with_net.md | 11 ++--- ...reating_lnk_file_in_suspicious_location.md | 13 ++---- ...8-27-exchange_powershell_abuse_via_ssrf.md | 11 ++--- ...-08-27-exchange_powershell_module_usage.md | 13 ++---- ...domain_controller_discovery_with_nltest.md | 11 ++--- ...-08-30-remote_system_discovery_with_net.md | 11 ++--- ...petitpotam_network_share_access_request.md | 11 ++--- ...itpotam_suspicious_kerberos_tgt_request.md | 11 ++--- ...31-remote_system_discovery_with_dsquery.md | 11 ++--- ...1-09-01-circle_ci_disable_security_step.md | 11 ++--- ...1-domain_controller_discovery_with_wmic.md | 11 ++--- ...-01-domain_group_discovery_with_dsquery.md | 13 ++---- ...adcomputer_with_powershell_script_block.md | 11 ++--- ...s_computer_with_powershell_script_block.md | 11 ++--- .../2021-09-01-github_commit_in_develop.md | 11 ++--- .../2021-09-01-github_dependabot_alert.md | 13 ++---- ...1-github_pull_request_from_unknown_user.md | 13 ++---- ...hash_observed_at_the_destination_device.md | 13 ++---- ..._observed_by_an_event_collecting_device.md | 13 ++---- ...mote_system_discovery_with_adsisearcher.md | 11 ++--- ...09-01-remote_system_discovery_with_wmic.md | 11 ++--- ...21-09-02-circle_ci_disable_security_job.md | 11 ++--- ...1-09-02-get-foresttrust_with_powershell.md | 11 ++--- ...oresttrust_with_powershell_script_block.md | 11 ++--- ...incomputer_with_powershell_script_block.md | 11 ++--- ...controller_with_powershell_script_block.md | 11 ++--- ...dd_defaultuser_and_password_in_registry.md | 13 ++---- ...1-09-06-auto_admin_logon_registry_entry.md | 13 ++---- ...cdedit_command_back_to_normal_mode_boot.md | 11 ++--- ...change_to_safe_mode_with_network_config.md | 11 ++--- ...9-06-correlation_by_repository_and_risk.md | 13 ++---- ...2021-09-06-correlation_by_user_and_risk.md | 13 ++---- ...021-09-07-getadcomputer_with_powershell.md | 11 ++--- ...09-07-getdomaincomputer_with_powershell.md | 11 ++--- ...-07-getdomaincontroller_with_powershell.md | 11 ++--- ...etwmiobject_ds_computer_with_powershell.md | 11 ++--- ...9-07-registry_keys_used_for_persistence.md | 13 ++---- ...e_by_app_connect_and_create_adsi_object.md | 13 ++---- ...-system_information_discovery_detection.md | 11 ++--- ...l_loading_from_world_writable_directory.md | 13 ++---- ...eate_local_admin_accounts_using_net_exe.md | 13 ++---- .../2021-09-08-office_spawning_control.md | 13 ++---- ...2021-09-08-rundll32_control_rundll_hunt.md | 13 ++---- ...control_rundll_world_writable_directory.md | 13 ++---- ...2021-09-09-extraction_of_registry_hives.md | 13 ++---- ...09-mshtml_module_load_in_office_product.md | 13 ++---- ...connection_with_powershell_script_block.md | 11 ++--- ...0-network_connection_discovery_with_arp.md | 11 ++--- ...0-network_connection_discovery_with_net.md | 11 ++--- ...twork_connection_discovery_with_netstat.md | 11 ++--- ...09-10-office_product_writing_cab_or_inf.md | 13 ++---- ...1-09-13-getcurrent_user_with_powershell.md | 11 ++--- ...rrent_user_with_powershell_script_block.md | 11 ++--- ...-13-jscript_execution_using_cscript_app.md | 13 ++---- ...s_scripting_process_loading_ldap_module.md | 13 ++---- ...ms_scripting_process_loading_wmi_module.md | 13 ++---- ...9-13-office_application_drop_executable.md | 13 ++---- ...-09-13-system_user_discovery_with_query.md | 11 ++--- ...09-13-system_user_discovery_with_whoami.md | 11 ++--- ...user_discovery_with_env_vars_powershell.md | 11 ++--- ...y_with_env_vars_powershell_script_block.md | 11 ++--- ...21-09-13-xsl_script_execution_with_wmic.md | 11 ++--- ...-cmdline_tool_not_executed_in_cmd_shell.md | 13 ++---- ...021-09-14-get_wmiobject_group_discovery.md | 13 ++---- ...oup_discovery_with_script_block_logging.md | 13 ++---- .../2021-09-14-net_localgroup_discovery.md | 13 ++---- ...-14-powershell_get_localgroup_discovery.md | 13 ++---- ...oup_discovery_with_script_block_logging.md | 13 ++---- .../_posts/2021-09-14-wmic_group_discovery.md | 13 ++---- ...1-09-15-check_elevated_cmd_using_whoami.md | 11 ++--- ...me_process_accessing_chrome_default_dir.md | 13 ++---- ...efox_process_access_firefox_profile_dir.md | 13 ++---- ...21-09-16-account_discovery_with_net_app.md | 13 ++---- ...t_to_add_certificate_to_untrusted_store.md | 13 ++---- ...edential_dump_from_registry_via_reg_exe.md | 13 ++---- ...2021-09-16-batch_file_write_to_system32.md | 13 ++---- .../_posts/2021-09-16-bits_job_persistence.md | 11 ++--- .../2021-09-16-bitsadmin_download_file.md | 14 ++----- ...of_shadow_copy_with_wmic_and_powershell.md | 13 ++---- ...mping_via_copy_command_from_shadow_copy.md | 13 ++---- ...tial_dumping_via_symlink_to_shadow_copy.md | 13 ++---- .../2021-09-16-detect_html_help_renamed.md | 13 ++---- ...16-detect_html_help_url_in_command_line.md | 13 ++---- ...ml_help_using_infotech_storage_handlers.md | 13 ++---- ...09-16-detect_mshta_inline_hta_execution.md | 13 ++---- .../_posts/2021-09-16-detect_mshta_renamed.md | 13 ++---- ...-09-16-detect_mshta_url_in_command_line.md | 13 ++---- ...9-16-detect_psexec_with_accepteula_flag.md | 13 ++---- .../_posts/2021-09-16-detect_renamed_7-zip.md | 13 ++---- .../2021-09-16-detect_renamed_psexec.md | 13 ++---- .../2021-09-16-detect_renamed_rclone.md | 11 ++--- .../2021-09-16-detect_renamed_winrar.md | 13 ++---- .../2021-09-16-dump_lsass_via_procdump.md | 13 ++---- ...-09-16-local_account_discovery_with_net.md | 13 ++---- ...09-16-local_account_discovery_with_wmic.md | 13 ++---- ...2021-09-16-office_product_spawning_wmic.md | 13 ++---- .../2021-09-16-processes_launching_netsh.md | 13 ++---- ...t_regasm_with_no_command_line_arguments.md | 13 ++---- ..._regsvcs_with_no_command_line_arguments.md | 13 ++---- ...ument_spawned_child_process_to_download.md | 13 ++---- ...cious_dllhost_no_command_line_arguments.md | 11 ++--- ...ious_gpupdate_no_command_line_arguments.md | 11 ++--- ...ious_microsoft_workflow_compiler_rename.md | 16 ++------ ...ious_rundll32_no_command_line_arguments.md | 13 ++---- ...hprotocolhost_no_command_line_arguments.md | 11 ++--- ...mcos_rat_file_creation_in_remcos_folder.md | 11 ++--- ...icious_image_creation_in_appdata_folder.md | 11 ++--- ...1-suspicious_wav_file_in_appdata_folder.md | 11 ++--- ...24-remcos_client_registry_install_entry.md | 11 ++--- ...1-09-27-change_default_file_association.md | 13 ++---- ...27-logon_script_event_trigger_execution.md | 13 ++---- ...-27-screensaver_event_trigger_execution.md | 13 ++---- ...1-09-28-active_setup_registry_autostart.md | 13 ++---- ...9-28-print_processor_registry_autostart.md | 13 ++---- ...21-09-29-disable_uac_remote_restriction.md | 13 ++---- ...9-29-time_provider_persistence_registry.md | 13 ++---- .../2021-09-29-verclsid_clsid_execution.md | 13 ++---- ...01-vbscript_execution_using_wscript_app.md | 13 ++---- ...ld_suspicious_spawned_by_script_process.md | 13 ++---- ...10-04-regsvr32_silent_param_dll_loading.md | 13 ++---- .../2021-10-05-detect_exchange_web_shell.md | 13 ++---- ...ble_security_logs_using_minint_registry.md | 11 ++--- ...ble_wdigest_uselogoncredential_registry.md | 14 ++----- ...5-malicious_inprocserver32_modification.md | 13 ++---- ..._connect_to_internet_with_hidden_window.md | 13 ++---- ...us_powershell_process_-_encoded_command.md | 11 ++--- ...1-10-05-process_writing_dynamicwrapperx.md | 13 ++---- .../2021-10-05-rundll32_shimcache_flush.md | 11 ++--- .../2021-10-05-suspicious_copy_on_system32.md | 13 ++---- .../2021-10-05-winhlp32_spawning_a_process.md | 11 ++--- ...ery_length_with_high_standard_deviation.md | 13 ++---- ...021-10-06-sdelete_application_execution.md | 16 ++------ ...ipt_or_cscript_suspicious_child_process.md | 19 ++------- .../2021-10-07-etw_registry_disabled.md | 16 ++------ .../2021-10-11-suspicious_wevtutil_usage.md | 13 ++---- ..._no_command_line_arguments_with_network.md | 11 ++--- ..._no_command_line_arguments_with_network.md | 13 ++---- ...lhost_with_no_command_line_with_network.md | 11 ++--- ...1-first_time_seen_command_line_argument.md | 17 ++------ docs/detections.wiki | 2 +- docs/stories.wiki | 2 +- 661 files changed, 1905 insertions(+), 6281 deletions(-) diff --git a/bin/jinja2_templates/doc_detections_markdown.j2 b/bin/jinja2_templates/doc_detections_markdown.j2 index cc8e1185d3..2ff549bef7 100644 --- a/bin/jinja2_templates/doc_detections_markdown.j2 +++ b/bin/jinja2_templates/doc_detections_markdown.j2 @@ -53,20 +53,21 @@ We have not been able to test, simulate or build datasets for it, use at your ow - **ID**: {{ detection.id }} {% if detection.mitre_attacks %} -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | {% for attack in detection.mitre_attacks -%} {% if attack.technique_id -%} -{%- set sub_technique = attack.technique_id.split('.') -%}{%- if sub_technique | length > 1 -%} +{% set sub_technique = attack.technique_id.split('.') -%} +{% if sub_technique | length > 1 -%} | [{{ attack.technique_id }}](https://attack.mitre.org/techniques/{{sub_technique[0]}}/{{sub_technique[1]}}/) | {{ attack.technique }} | {{ attack.tactic|join(', ') }} | -{% else %} +{% else -%} | [{{ attack.technique_id }}](https://attack.mitre.org/techniques/{{attack.technique_id}}/) | {{ attack.technique }} | {{ attack.tactic|join(', ') }} | -{% endif %} -{% endif %} +{% endif -%} +{% endif -%} {% endfor %} -{% endif %} +{% endif -%} #### Search @@ -128,4 +129,5 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith * [{{dataset}}]({{ dataset }}) {% endfor %} + [*source*](https://github.com/splunk/security_content/tree/develop/detections/{% if detection.experimental is sameas true -%}experimental/{%- endif -%}{{detection.kind}}/{{ detection.name | lower | replace (" ", "_") }}.yml) \| *version*: **{{detection.version}}** diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md index 7352d879af..aebabeeb53 100644 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md @@ -32,8 +32,6 @@ The search queries the authentication logs for assets that are categorized as ro - **Author**: Bhavin Patel, Splunk - **ID**: 104658f4-afdc-499e-9719-17243rr826f1 - - #### Search ``` diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md index f4d78c9271..fb7f72b06d 100644 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md @@ -34,8 +34,6 @@ By populating the organization's assets within the assets_by_str.csv, we wil - **Author**: Bhavin Patel, Splunk - **ID**: dcfd6b40-42f9-469d-a433-2e53f7489ff4 - - #### Search ``` diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md index 2d312c2e28..75daa76092 100644 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md @@ -31,8 +31,6 @@ This search looks for Windows endpoints that have not generated an event indicat - **Author**: Bhavin Patel, Splunk - **ID**: 1a77c08c-2f56-409c-a2d3-7d64617edd4f - - #### Search ``` diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md index 808690ec16..b17032fe99 100644 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md @@ -32,8 +32,6 @@ Attackers often use spaces as a means to obfuscate an attachment's file exte - **Author**: David Dorsey, Splunk - **ID**: 56e877a6-1455-4479-ada6-0550dc1e22f8 - - #### Search ``` diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index b723bcfbdc..664b8e35df 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -39,20 +39,13 @@ The search is used to identify attempts to use your DNS Infrastructure for DDoS - **ID**: 8fa891f7-a533-4b3c-af85-5aa2e7c1f1eb -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - - | [T1498.002](https://attack.mitre.org/techniques/T1498/002/) | Reflection Amplification | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md index 87a83433f0..dd88ccdfd0 100644 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md @@ -36,17 +36,12 @@ This search looks for specific GET or HEAD requests to web servers that are indi - **ID**: 104658f4-afdc-499e-9719-17243f982681 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md index ce1a379a1a..1d23d76854 100644 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md @@ -32,8 +32,6 @@ This search is used to detect malicious HTTP requests crafted to exploit jmx-con - **Author**: Bhavin Patel, Splunk - **ID**: c8bff7a4-11ea-4416-a27d-c5bca472913d - - #### Search ``` diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index 0bb9c7af0d..e1de0ad8bf 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -32,8 +32,6 @@ This search looks for Web requests to faux domains similar to the one that you w - **Author**: David Dorsey, Splunk - **ID**: 134da869-e264-4a8f-8d7e-fcd0ec88f301 - - #### Search ``` diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md index 42db79bc1e..fcea4fb6a5 100644 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md @@ -31,8 +31,6 @@ This search looks for unusually long strings in the Content-Type http header tha - **Author**: Bhavin Patel, Splunk - **ID**: 57a0a2bf-353f-40c1-84dc-29293f3c35b7 - - #### Search ``` diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md index 18e6fe2899..1bf0fbef1e 100644 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md @@ -32,8 +32,6 @@ This search looks for emails claiming to be sent from a domain similar to one th - **Author**: David Dorsey, Splunk - **ID**: b2ea1f38-3a3e-4b8a-9cf1-82760d86a6b8 - - #### Search ``` diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md index 26921a3a47..6998c388c5 100644 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md @@ -32,8 +32,6 @@ This search will detect spike in blocked outbound network connections originatin - **Author**: Bhavin Patel, Splunk - **ID**: ada0f278-84a8-46w1-a3f1-w32372d4bd53 - - #### Search ``` diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md index 0b663b625a..b524472042 100644 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md @@ -36,17 +36,12 @@ This search looks for outbound ICMP packets with a packet size larger than 1,000 - **ID**: e9c102de-4d43-42a7-b1c8-8062ea297419 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1095](https://attack.mitre.org/techniques/T1095/) | Non-Application Layer Protocol | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md index 08904bbee4..b917a081fb 100644 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md @@ -35,17 +35,12 @@ This search looks at S3 bucket-access logs and detects new or previously unseen - **ID**: 2a9b80d3-6340-4345-b5ad-291bq3d0daq4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md index 849f13f22f..8876b6b1f1 100644 --- a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md +++ b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md @@ -30,8 +30,6 @@ This search looks for cloud compute instances being created with previously unse - **Author**: David Dorsey, Splunk - **ID**: bc24922d-987c-4645-b288-f8c73ec194c4 - - #### Search ``` diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index 1798e29fbf..bb5885bcd3 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -35,17 +35,12 @@ This search looks for the creation of WMI permanent event subscriptions. - **ID**: 71bfdb13-f200-4c6c-b2c9-a2e07adf437d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index bf1a999f86..4477fb6cb3 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -35,17 +35,12 @@ This search looks for the creation of WMI temporary event subscriptions. - **ID**: 38cbd42c-1098-41bb-99cf-9d6d2b296d83 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md index 6c2914e8e3..6cdeabdf93 100644 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md @@ -35,17 +35,12 @@ This search detects users creating spikes in API activity related to deletion of - **ID**: ad12w478-84a8-4641-a3w1-e32372q4bd53 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md index 6a8ef63ad1..85d8c125ba 100644 --- a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md +++ b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md @@ -34,17 +34,12 @@ The following analytic identifies usage of `wmic.exe` spawning a local or remote - **ID**: 272df6de-61f1-4784-877c-1fbc3e2d0838 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2018-12-03-usn_journal_deletion.md b/docs/_posts/2018-12-03-usn_journal_deletion.md index 86ed279fcc..475fc4559c 100644 --- a/docs/_posts/2018-12-03-usn_journal_deletion.md +++ b/docs/_posts/2018-12-03-usn_journal_deletion.md @@ -34,17 +34,12 @@ The fsutil.exe application is a legitimate Windows utility used to perform tasks - **ID**: b6e0ff70-b122-4227-9368-4cf322ab43c3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 9b9fc4a6fb..b1a50655d6 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -31,8 +31,6 @@ This search looks for suspicious Java classes that are often used to exploit rem - **Author**: Jose Hernandez, Splunk - **ID**: if1fea6da-3c86-4c1d-b255-fc3b2781a491 - - #### Search ``` diff --git a/docs/_posts/2018-12-14-file_with_samsam_extension.md b/docs/_posts/2018-12-14-file_with_samsam_extension.md index 48bec4316b..1ce493000c 100644 --- a/docs/_posts/2018-12-14-file_with_samsam_extension.md +++ b/docs/_posts/2018-12-14-file_with_samsam_extension.md @@ -30,8 +30,6 @@ The search looks for file writes with extensions consistent with a SamSam ransom - **Author**: Rico Valdez, Splunk - **ID**: 02c6cfc2-ae66-4735-bfc7-6291da834cbf - - #### Search ``` diff --git a/docs/_posts/2018-12-14-samsam_test_file_write.md b/docs/_posts/2018-12-14-samsam_test_file_write.md index 18e4da5802..5cdee21915 100644 --- a/docs/_posts/2018-12-14-samsam_test_file_write.md +++ b/docs/_posts/2018-12-14-samsam_test_file_write.md @@ -34,17 +34,12 @@ The search looks for a file named "test.txt" written to the windows syst - **ID**: 493a879d-519d-428f-8f57-a06a0fdc107e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md index af0a162c31..c86c16b90b 100644 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md @@ -31,8 +31,6 @@ This search looks for processes in an MacOS system that is tapping keyboard even - **Author**: Jose Hernandez, Splunk - **ID**: 2a371608-331d-4034-ae2c-21dda8f1d0ec - - #### Search ``` diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md index 1840f20bca..79b1ab40bd 100644 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md @@ -36,17 +36,12 @@ This search looks for suspicious processes on all systems labeled as web servers - **ID**: ec3b7601-689a-4463-94e0-c9f45638efb9 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md index ed517cbe44..beb2559ae5 100644 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md @@ -31,8 +31,6 @@ Command lines that are extremely long may be indicative of malicious activity on - **Author**: Rico Valdez, Splunk - **ID**: 57edaefa-a73b-45e5-bbae-f39c1473f941 - - #### Search ``` diff --git a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md index fb40deac49..db97c1bab8 100644 --- a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md +++ b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md @@ -36,20 +36,13 @@ This search looks for reading lsass memory consistent with credential dumping. - **ID**: 2c365e57-4414-4540-8dc0-73ab10729996 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md index e27131660c..e4e9404a4a 100644 --- a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md +++ b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md @@ -36,20 +36,13 @@ This search looks for reading loaded Images unique to credential dumping with Mi - **ID**: 29e307ba-40af-4ab2-91b2-3c6b392bbba0 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md index d5b2cfbb52..4fe3b9d5d5 100644 --- a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md +++ b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md @@ -36,20 +36,13 @@ Detect memory dumping of the LSASS process. - **ID**: fb4c31b0-13e8-4155-8aa5-24de4b8d6717 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md index 593eb22987..017ecee9da 100644 --- a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md +++ b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md @@ -36,20 +36,13 @@ Detect remote thread creation into LSASS consistent with credential dumping. - **ID**: 67d4dbef-9564-4699-8da8-03a151529edc -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2019-12-10-creation_of_shadow_copy.md b/docs/_posts/2019-12-10-creation_of_shadow_copy.md index 5c2fa9781e..b14cfe82a3 100644 --- a/docs/_posts/2019-12-10-creation_of_shadow_copy.md +++ b/docs/_posts/2019-12-10-creation_of_shadow_copy.md @@ -37,20 +37,13 @@ Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy. - **ID**: eb120f5f-b879-4a63-97c1-93352b5df844 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index c7d4fd67ca..ab86b4ed3a 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -39,20 +39,13 @@ This search allows you to identify DNS requests that are unusually large for the - **ID**: 85fbcfe8-9718-4911-adf6-7000d077a3a9 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | - - - | [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md index 3d7b3a22a2..957084bb62 100644 --- a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md +++ b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md @@ -36,20 +36,13 @@ Detect the hands on keyboard behavior of Windows Task Manager creating a process - **ID**: b2fbe95a-9c62-4c12-8a29-24b97e84c0cd -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md index d79f0b644f..a7186ca3e3 100644 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md @@ -33,8 +33,6 @@ This search looks for processes referencing the plist files that determine which - **Author**: Jamie Windley, Splunk - **ID**: 40bb64f9-f619-4e3d-8732-328d40377c4b - - #### Search ``` diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md index 43350f0f8c..31c9147d0d 100644 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md @@ -34,17 +34,12 @@ This searches show information on uploaded containers including source user, ima - **ID**: f0f70b40-f7ad-489d-9905-23d149da8099 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1525](https://attack.mitre.org/techniques/T1525/) | Implant Internal Image | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md index 2517e0d11f..55cadc4210 100644 --- a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md +++ b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md @@ -37,20 +37,13 @@ Detect the usage of comsvcs.dll for dumping the lsass process. - **ID**: 8943b567-f14d-4ee8-a0bb-2121d4ce3184 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md index 9ef2ff1c43..e20c971415 100644 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md @@ -37,17 +37,12 @@ This search looks for child processes of spoolsv.exe. This activity is associate - **ID**: aa0c4aeb-5b18-41c4-8c07-f1442d7599df -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md index c309831077..ce94f6580f 100644 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ b/docs/_posts/2020-03-16-detect_rare_executables.md @@ -34,8 +34,6 @@ This search will return a table of rare processes, the names of the systems runn - **Author**: Bhavin Patel, Splunk - **ID**: 44fddcb2-8d3b-454c-874e-7c6de5a4f7ac - - #### Search ``` diff --git a/docs/_posts/2020-03-16-process_execution_via_wmi.md b/docs/_posts/2020-03-16-process_execution_via_wmi.md index f663951560..865c2472ef 100644 --- a/docs/_posts/2020-03-16-process_execution_via_wmi.md +++ b/docs/_posts/2020-03-16-process_execution_via_wmi.md @@ -34,17 +34,12 @@ The following analytic identifies `WmiPrvSE.exe` spawning a process. This typica - **ID**: 24869767-8579-485d-9a4f-d9ddfd8f0cac -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-03-16-script_execution_via_wmi.md b/docs/_posts/2020-03-16-script_execution_via_wmi.md index 87bb411662..6170b70137 100644 --- a/docs/_posts/2020-03-16-script_execution_via_wmi.md +++ b/docs/_posts/2020-03-16-script_execution_via_wmi.md @@ -34,17 +34,12 @@ This search looks for scripts launched via WMI. - **ID**: aa73f80d-d728-4077-b226-81ea0c8be589 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md index 6311c9638b..05e1916bdd 100644 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ b/docs/_posts/2020-03-16-spike_in_file_writes.md @@ -31,8 +31,6 @@ The search looks for a sharp increase in the number of files written to a partic - **Author**: David Dorsey, Splunk - **ID**: fdb0f805-74e4-4539-8c00-618927333aae - - #### Search ``` diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index 4dcec2ff04..9c2b2696f1 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -35,17 +35,12 @@ This search provides information of unauthenticated requests via user agent, and - **ID**: 294c4686-63dd-4fe6-93a2-ca807626704a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index 8e0a80582e..a2b3a7befa 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -35,17 +35,12 @@ This search provides detection information on unauthenticated requests against K - **ID**: dbfca1dd-b8e5-4ba4-be0e-e565e5d62002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index 6a384190e5..be66a3fd36 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -34,17 +34,12 @@ This search looks for child processes spawned by zoom.exe or zoom.us that has no - **ID**: e91bd102-d630-4e76-ab73-7e3ba22c5961 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md index fd00890a51..376cbfc5d5 100644 --- a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md +++ b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md @@ -31,8 +31,6 @@ This search looks for AssumeRole events where an IAM role in a different account - **Author**: Rico Valdez, Splunk - **ID**: 21193641-cb96-4a2c-a707-d9b9a7f7792b - - #### Search ``` diff --git a/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md b/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md index b16f799e8d..fd445bd6f6 100644 --- a/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md +++ b/docs/_posts/2020-05-28-detect_aws_console_login_by_new_user.md @@ -31,8 +31,6 @@ This search looks for AWS CloudTrail events wherein a console login event by a u - **Author**: Rico Valdez, Splunk - **ID**: bc91a8cd-35e7-4bb2-6140-e756cc46fd71 - - #### Search ``` diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md index 8b2348211a..e55dfcbebe 100644 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md @@ -31,8 +31,6 @@ This search provides information on anonymous Kubectl calls with IP, verb namesp - **Author**: Rod Soto, Splunk - **ID**: 042a3d32-8318-4763-9679-09db2644a8f2 - - #### Search ``` diff --git a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md index 60a0b91064..e37ce29976 100644 --- a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md +++ b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md @@ -41,20 +41,13 @@ The detection Detect Path Interception By Creation Of program exe is detecting t - **ID**: c77162d3-f93c-45cc-80c8-22f6v5264g9f -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1574.009](https://attack.mitre.org/techniques/T1574/009/) | Path Interception by Unquoted Path | Persistence, Privilege Escalation, Defense Evasion | - - - | [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-06-short_lived_windows_accounts.md b/docs/_posts/2020-07-06-short_lived_windows_accounts.md index 7046f7527e..5992dc69a3 100644 --- a/docs/_posts/2020-07-06-short_lived_windows_accounts.md +++ b/docs/_posts/2020-07-06-short_lived_windows_accounts.md @@ -36,20 +36,13 @@ This search detects accounts that were created and deleted in a short time perio - **ID**: b25f6f62-0782-43c1-b403-083231ffd97d -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md index 30d3fe723a..7983d07be0 100644 --- a/docs/_posts/2020-07-06-windows_event_log_cleared.md +++ b/docs/_posts/2020-07-06-windows_event_log_cleared.md @@ -36,20 +36,13 @@ The following analytic utilizes Windows Security Event ID 1102 or System log eve - **ID**: ad517544-aff9-4c96-bd99-d6eb43bfbb6a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index af390754cc..447a6adfb4 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -39,20 +39,13 @@ This search looks for network traffic on TCP/3389, the default port used by remo - **ID**: 272b8407-842d-4b3d-bead-a704584003d3 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-08-detect_new_local_admin_account.md b/docs/_posts/2020-07-08-detect_new_local_admin_account.md index cd4191b738..a00ad5f175 100644 --- a/docs/_posts/2020-07-08-detect_new_local_admin_account.md +++ b/docs/_posts/2020-07-08-detect_new_local_admin_account.md @@ -37,20 +37,13 @@ This search looks for newly created accounts that have been elevated to local ad - **ID**: b25f6f62-0712-43c1-b203-083231ffd97d -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md index bb4d102a2a..049171f26a 100644 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md @@ -35,17 +35,12 @@ This search provides information of unauthenticated requests via user agent, and - **ID**: 19b53215-4a16-405b-8087-9e6acf619842 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md index d811d0844a..b293c28626 100644 --- a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md +++ b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md @@ -38,20 +38,13 @@ This search looks for attempts to stop security-related services on the endpoint - **ID**: c8e349c6-b97c-486e-8949-bd7bcd1f3910 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md index 27cf64b914..308b60e23e 100644 --- a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md +++ b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md @@ -42,20 +42,13 @@ This search detects user accounts that have been locked out a relatively high nu - **ID**: 95a7f9a5-6096-437e-a19e-86f42ac609bd -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1078.003](https://attack.mitre.org/techniques/T1078/003/) | Local Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index 10c426ffec..b1509a6514 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -40,20 +40,13 @@ This search looks for outbound SMB connections made by hosts within your network - **ID**: 7f5fb3e1-4209-414-90db-0ec21b936378 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1071.002](https://attack.mitre.org/techniques/T1071/002/) | File Transfer Protocols | Command And Control | - - - | [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index 1dc0a63638..bf6f645f79 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -39,20 +39,13 @@ This search looks for execution of process `outlook.exe` where the process is wr - **ID**: a51bfe1a-94f0-4822-b1e4-16ae10145893 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md index c01f518624..b162b1cdd3 100644 --- a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md +++ b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md @@ -37,20 +37,13 @@ This search looks for the execution of the cscript.exe or wscript.exe processes, - **ID**: b89919ed-fe5f-492c-b139-95dbb162039e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md index 28cf5587e3..25147788c7 100644 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md @@ -38,17 +38,12 @@ This search looks for specific command-line arguments that may indicate the exec - **ID**: 1297fb80-f42a-4q4a-9c8b-78c061417cf6 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1072](https://attack.mitre.org/techniques/T1072/) | Software Deployment Tools | Execution, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index 0f52a2346a..a84ae6e353 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -39,20 +39,13 @@ The search looks at the change-analysis data model and detects email files creat - **ID**: ee18ed37-0802-4268-9435-b3b91aaa18xx -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - | [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index f0e9f2151a..3fbccd967e 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -39,20 +39,13 @@ This search looks for an increase of data transfers from your email server to yo - **ID**: 7f5fb3e1-4209-4914-90db-0ec21b556378 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - | [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index c0bbe6ee27..dfce7f0d68 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -39,20 +39,13 @@ This search identifies DNS query failures by counting the number of DNS response - **ID**: 104658f4-afdc-499e-9719-17243f9826f1 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1071.004](https://attack.mitre.org/techniques/T1071/004/) | DNS | Command And Control | - - - | [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index d2238fbc53..ca02023cbb 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -39,20 +39,13 @@ This search looks for the first and last time a Windows service is seen running - **ID**: 823136f2-d755-4b6d-ae04-372b486a5808 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md index 55be144660..42119d187a 100644 --- a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md +++ b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md @@ -37,20 +37,13 @@ Attackers leverage an existing Windows binary, attrib.exe, to mark specific as h - **ID**: c77162d3-f93c-45cc-80c8-22f6b5264g9f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - | [T1222.001](https://attack.mitre.org/techniques/T1222/001/) | Windows File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index f1f4ac485d..b2e35b8c74 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -39,20 +39,13 @@ This search looks for an increase of data transfers from your email server to yo - **ID**: 7f5fb3e1-4209-4914-90db-0ec21b556368 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | - - - | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md index 95de135498..1048968abe 100644 --- a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md +++ b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md @@ -38,20 +38,13 @@ This search looks for PowerShell processes started with parameters used to bypas - **ID**: 9be56c82-b1cc-4318-87eb-d138afaaca39 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 4adc8781ed..c7fe183434 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -43,20 +43,13 @@ This search detects Okta login failures due to bad credentials for multiple user - **ID**: 19cba45f-cad3-4032-8911-0c09e0444552 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index 29ee75b530..d3a121e429 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -43,20 +43,13 @@ Detect Okta user lockout events - **ID**: 62b70968-a0a5-4724-8ac4-67871e6f544d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index 1eb506d0df..27575e3d9c 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -43,20 +43,13 @@ Detect failed Okta SSO events - **ID**: 371a6545-2618-4032-ad84-93386b8698c5 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index 5c665bcba2..7c46df7407 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -43,20 +43,13 @@ This search detects logins from the same user from different cities in a 24 hour - **ID**: 7594fa07-9f34-4d01-81cc-d6af6a5db9e8 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1078.001](https://attack.mitre.org/techniques/T1078/001/) | Default Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md index 4204a59351..140a347542 100644 --- a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md +++ b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md @@ -39,20 +39,13 @@ Microsoft Windows contains accessibility features that can be launched with a ke - **ID**: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - | [T1546.008](https://attack.mitre.org/techniques/T1546/008/) | Accessibility Features | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md index b33806b83c..2bd0ca9e6a 100644 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md @@ -37,17 +37,12 @@ This search looks for network traffic defined by port and transport layer protoc - **ID**: ce5a0962-849f-4720-a678-753fe6674479 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index 1742d5d0ff..a670179b4f 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -39,20 +39,13 @@ This search looks for network traffic on common ports where a higher layer proto - **ID**: 54dc1265-2f74-4b6d-b30d-49eb506a31b3 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | - - - | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index ce6e3a2588..6e69552a91 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -40,20 +40,13 @@ This search looks for RDP application network traffic and filters any source/des - **ID**: a98727cc-286b-4ff2-b898-41df64695923 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index 44f00e1416..fff6fb28d5 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -39,20 +39,13 @@ This search looks for the remote desktop process mstsc.exe running on systems up - **ID**: f5939373-8054-40ad-8c64-cec478a22a4a -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md index 7ef0eaf770..206963160a 100644 --- a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md +++ b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md @@ -39,20 +39,13 @@ This search looks for arguments to sc.exe indicating the creation or modificatio - **ID**: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md index 25c04dfbac..ddf98f94f8 100644 --- a/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md +++ b/docs/_posts/2020-07-21-schtasks_scheduling_job_on_remote_system.md @@ -41,20 +41,13 @@ This search looks for flags passed to schtasks.exe on the command-line that indi - **ID**: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md index 57ae1d7c14..e67677c820 100644 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md @@ -36,17 +36,12 @@ This search looks for long URLs that have several SQL commands visible within th - **ID**: e0aad4cf-0790-423b-8328-7564d0d938f9 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index 1c95caa1e6..938d9d204d 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -39,20 +39,13 @@ This search looks for spikes in the number of Server Message Block (SMB) traffic - **ID**: 7f5fb3e1-4209-4914-90db-0ec21b936378 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index 80cb7fdc11..9d06715fdf 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -39,20 +39,13 @@ This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the n - **ID**: d25773ba-9ad8-48d1-858e-07ad0bbeb828 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index 3123481db1..149be5d996 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -39,20 +39,13 @@ This search looks for emails that have attachments with suspicious file extensio - **ID**: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md index 51ed95ce53..b762264907 100644 --- a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md +++ b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md @@ -34,17 +34,12 @@ This search looks for reg.exe being launched from a command prompt not started b - **ID**: a6b3ab4e-dd77-4213-95fa-fc94701995e0 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md index 09f5c86ed1..ca6330de87 100644 --- a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md +++ b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md @@ -32,17 +32,12 @@ This search detects writes to the recycle bin by a process other than explorer.e - **ID**: b5541828-8ffd-4070-9d95-b3da4de924cb -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index 6c15cdf490..2e71c7449b 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -39,20 +39,13 @@ This search looks for network traffic identified as The Onion Router (TOR), a be - **ID**: ea688274-9c06-4473-b951-e4cb7a5d7a45 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1071](https://attack.mitre.org/techniques/T1071/) | Application Layer Protocol | Command And Control | - - | [T1071.001](https://attack.mitre.org/techniques/T1071/001/) | Web Protocols | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md index 3075ba7704..50f87ce101 100644 --- a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md +++ b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md @@ -37,20 +37,13 @@ Attackers often disable security tools to avoid detection. This search looks for - **ID**: c77162d3-f93c-45cc-80c8-22f665664g9f -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md index dc4b957850..9aa3857439 100644 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md @@ -38,17 +38,12 @@ This search provides detection of an user attaching itself to a different role t - **ID**: 88fc31dd-f331-448c-9856-d3d51dd5d3a1 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md index fd58811fb3..9c48e4a858 100644 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md @@ -38,17 +38,12 @@ This search provides detection of accounts creating permanent keys. Permanent ke - **ID**: 12d6d713-3cb4-4ffc-a064-1dca3d1cca01 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md index abde17faab..5a20c9d58a 100644 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md @@ -38,17 +38,12 @@ This search provides detection of role creation by IAM users. Role creation is a - **ID**: 5f04081e-ddee-4353-afe4-504f288de9ad -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md index 62b26bee59..c436d580ed 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md @@ -38,17 +38,12 @@ This search provides detection of suspicious use of sts:AssumeRole. These tokens - **ID**: 8e565314-b6a2-46d8-9f05-1a34a176a662 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md index 6b415bd65e..159fe5f46f 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md @@ -36,17 +36,12 @@ This search provides detection of suspicious use of sts:GetSessionToken. These t - **ID**: 85d7b35f-b8b5-4b01-916f-29b81e7a0551 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index f7b40554af..9eace607cb 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -36,17 +36,12 @@ This search detects SIGRed via Splunk Stream. - **ID**: babd8d10-d073-11ea-87d0-0242ac130003 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md index c73b07bf86..92ed8ff770 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md @@ -37,17 +37,12 @@ This search detects SIGRed via Zeek DNS and Zeek Conn data. - **ID**: c5c622e4-d073-11ea-87d0-0242ac130003 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md index 7b94dc2969..fcb17000ae 100644 --- a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md +++ b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md @@ -43,20 +43,13 @@ This search looks for cloud instances being modified by users who have not previ - **ID**: 7fb15084-b14e-405a-bd61-a6de15a40722 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md index 1035dc10ee..0882f01a97 100644 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md @@ -36,17 +36,12 @@ This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traff - **ID**: 810e4dbc-d46e-11ea-87d0-0242ac130003 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md index 7ff5f21392..87ad754bcd 100644 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md @@ -35,17 +35,12 @@ This search looks for GCP PubSub events where a user has created an open/public - **ID**: f6ea3466-d6bb-11ea-87d0-0242ac130003 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index bb0f93af01..f8d6fe00cf 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -35,17 +35,12 @@ This search looks at GCP Storage bucket-access logs and detects new or previousl - **ID**: ccc3246a-daa1-11ea-87d0-0242ac130022 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index 03d9cb978d..5ae062d944 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -48,28 +48,15 @@ By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organiza - **ID**: b44bebd6-bd39-467b-9321-73971bcd7aac -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - - - | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - - - | [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | - - | [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Credential Access, Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md index 399a994ef5..4060228526 100644 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md @@ -44,25 +44,14 @@ By enabling DHCP Snooping as a Layer 2 Security measure on the organization' - **ID**: 6e1ada88-7a0d-4ac1-92c6-03d354686079 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - - - | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - - - | [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md index 38f51c5a6c..af736d898b 100644 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md +++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md @@ -37,17 +37,12 @@ This search looks for cloud provisioning activities from previously unseen IP ad - **ID**: f86a8ec9-b042-45eb-92f4-e9ed1d781078 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md index c29c010de4..3c4dabb1a7 100644 --- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md +++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md @@ -37,17 +37,12 @@ This search looks for cloud provisioning activities from previously unseen regio - **ID**: 5aba1860-9617-4af9-b19d-aecac16fe4f2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index c590bfb723..b7078be64c 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -46,20 +46,13 @@ This search finds for the number successfully destroyed cloud instances for ever - **ID**: ef629fc9-1583-4590-b62a-f2247fbf7bbf -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index 9e22c841b2..a633814bcd 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -46,20 +46,13 @@ This search finds for the number successfully created cloud instances for every - **ID**: f2361e9f-3928-496c-a556-120cd4223a65 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-25-more_than_usual_number_of_lolbas_applications_in_short_time_period.md b/docs/_posts/2020-08-25-more_than_usual_number_of_lolbas_applications_in_short_time_period.md index 9d24f55314..240bb4c4a1 100644 --- a/docs/_posts/2020-08-25-more_than_usual_number_of_lolbas_applications_in_short_time_period.md +++ b/docs/_posts/2020-08-25-more_than_usual_number_of_lolbas_applications_in_short_time_period.md @@ -36,21 +36,13 @@ Attacker activity may compromise executing several LOLBAS applications in conjun - **ID**: 59c0dd70-169c-4900-9a1f-bfcf13302f93 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md index f0ad0597d9..8a5eb9c433 100644 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md @@ -33,17 +33,12 @@ Malicious mails can conduct phishing that induces readers to open attachment, cl - **ID**: 4b237388-dfa1-41a6-91d4-4de2d598376f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md b/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md index 81c7b17c43..951de628cb 100644 --- a/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md +++ b/docs/_posts/2020-08-25-system_process_running_from_unexpected_location.md @@ -31,17 +31,12 @@ An attacker tries might try to use different version of a system command without - **ID**: 28179107-099a-464a-94d3-08301e6c055f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md index 65ea91d39c..deb7bc70ec 100644 --- a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md +++ b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md @@ -35,17 +35,12 @@ This search looks at cloud-infrastructure events where an instance is created in - **ID**: fa4089e2-50e3-40f7-8469-d2cc1564ca59 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md index bf79b26d73..a0d7b4ac52 100644 --- a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md +++ b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md @@ -37,17 +37,12 @@ This search looks for new commands from each user role. - **ID**: 2181ad1f-1e73-4d0c-9780-e8880482a08f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md index effbbd37ed..a50b9ce6e5 100644 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md +++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md @@ -44,20 +44,13 @@ This search will detect a spike in the number of API calls made to your cloud in - **ID**: 0840ddf1-8c89-46ff-b730-c8d6722478c0 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md index e4f393580f..66dcf1c0b4 100644 --- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md +++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md @@ -44,20 +44,13 @@ This search will detect a spike in the number of API calls made to your cloud in - **ID**: d4dfb7f3-7a37-498a-b5df-f19334e871af -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md index 6c405321de..801da840ad 100644 --- a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md +++ b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md @@ -30,8 +30,6 @@ Find EC2 instances being created with previously unseen instance types. - **Author**: David Dorsey, Splunk - **ID**: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda - - #### Search ``` diff --git a/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md b/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md index 8997c70b27..560d4ac381 100644 --- a/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md +++ b/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md @@ -34,20 +34,13 @@ This search detects the memory of lsass.exe being dumped for offline credential - **ID**: 76bb9e35-f314-4c3d-a385-83c72a13ce4e -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md index 2035905f5e..9c7beb6f65 100644 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md @@ -36,17 +36,12 @@ This search detects attempts to run exploits for the Zerologon CVE-2020-1472 vul - **ID**: bf7a06ec-f703-11ea-adc1-0242ac120002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md index 57e3bc7984..0d16517b0a 100644 --- a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md +++ b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md @@ -37,20 +37,13 @@ This search looks for the creation or deletion of hidden shares using net.exe. - **ID**: qw9919ed-fe5f-492c-b139-151bb162140e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - | [T1070.005](https://attack.mitre.org/techniques/T1070/005/) | Network Share Connection Removal | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index f612f4ebbd..ce257d7b8a 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -34,17 +34,12 @@ This search looks for Event Code 4742 (Computer Change) or EventCode 4624 (An ac - **ID**: 1400624a-d42d-484d-8843-e6753e6e3645 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1210](https://attack.mitre.org/techniques/T1210/) | Exploitation of Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-06-unusually_long_command_line.md b/docs/_posts/2020-10-06-unusually_long_command_line.md index 5df4c45da1..8b8789a401 100644 --- a/docs/_posts/2020-10-06-unusually_long_command_line.md +++ b/docs/_posts/2020-10-06-unusually_long_command_line.md @@ -27,8 +27,6 @@ Command lines that are extremely long may be indicative of malicious activity on - **Author**: Ignacio Bermudez Corrales, Splunk - **ID**: 58f43aba-1775-445e-b19c-be2b87d83ae3 - - #### Search ``` diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md index 5a406fb90f..5c4997823e 100644 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md +++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md @@ -35,17 +35,12 @@ This search looks for AWS CloudTrail events wherein a console login event by a u - **ID**: 121b0b11-f8ac-4ed6-a132-3800ca4fc07a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md index e8ca6faff0..970ffac505 100644 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md +++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md @@ -35,17 +35,12 @@ This search looks for AWS CloudTrail events wherein a console login event by a u - **ID**: 67bd3def-c41c-4bf6-837b-ae196b4257c6 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md index 655a0a1b0a..7a8a6633d3 100644 --- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md +++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md @@ -35,17 +35,12 @@ This search looks for AWS CloudTrail events wherein a console login event by a u - **ID**: 9f31aa8e-e37c-46bc-bce1-8b3be646d026 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1535](https://attack.mitre.org/techniques/T1535/) | Unused/Unsupported Cloud Regions | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md index ee78e118f3..558b24bd5b 100644 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md @@ -38,17 +38,12 @@ This search provides detection of GCPloit exploitation framework. This framework - **ID**: a1c5a85e-a162-410c-a5d9-99ff639e5a52 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md index 2a56c547f8..dc923d2bc2 100644 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md +++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md @@ -37,17 +37,12 @@ This search looks for cloud provisioning activities from previously unseen citie - **ID**: e7ecc5e0-88df-48b9-91af-51104c68f02f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md index 46a2283d61..82b426c823 100644 --- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md +++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md @@ -37,17 +37,12 @@ This search looks for cloud provisioning activities from previously unseen count - **ID**: 94994255-3acf-4213-9b3f-0494df03bb31 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md index cb51e97ff3..3100857549 100644 --- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md +++ b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md @@ -38,20 +38,13 @@ This search looks for specific authentication events from the Windows Security E - **ID**: f5939373-8054-40ad-8c64-cec478a22a4b -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - - | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md b/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md index a15f01c783..f085a5fe57 100644 --- a/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md +++ b/docs/_posts/2020-10-16-kerberoasting_spn_request_with_rc4_encryption.md @@ -36,20 +36,13 @@ This search detects a potential kerberoasting attack via service principal name - **ID**: 5cc67381-44fa-4111-8a37-7a230943f027 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - - - | [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md b/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md index 40b02fe9f1..13ec1d0524 100644 --- a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md +++ b/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 312582f2-5e91-42c1-a275-cd67f31373c8 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md b/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md index 8e0b67f013..92efc88ff6 100644 --- a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md +++ b/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md b/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md index 1fd84f72ac..2a2abf4d11 100644 --- a/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md +++ b/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md @@ -34,21 +34,13 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 341975fa-4ad0-4f01-9acc-df4f69742db7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - | [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md b/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md index 55527f4e6b..7c4691ef90 100644 --- a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md +++ b/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md b/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md index f17b2a8df0..ff81a431ae 100644 --- a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md +++ b/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: adc51a77-90c9-4358-b43c-f10dd1a27d05 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md b/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md index 52aac9d174..8019e7a9aa 100644 --- a/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md +++ b/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md index cf0418070b..233965819d 100644 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md +++ b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md index 796ee37568..e3917d5ef0 100644 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md +++ b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md index 6cdc76c669..28c5c72113 100644 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md +++ b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md index 032e07fe84..a25a8d73ba 100644 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md +++ b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md @@ -31,17 +31,12 @@ Credential extraction is often an illegal recovery of credential material from s - **ID**: 5f1186a4-e681-446e-851c-dc9574ad28eb -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-detect_kerberoasting.md b/docs/_posts/2020-10-21-detect_kerberoasting.md index 653faaf139..709ace04a8 100644 --- a/docs/_posts/2020-10-21-detect_kerberoasting.md +++ b/docs/_posts/2020-10-21-detect_kerberoasting.md @@ -34,20 +34,13 @@ This search detects a potential kerberoasting attack via service principal name - **ID**: dabdd6d7-3e10-42be-8711-4e124f7a3850 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1558.003](https://attack.mitre.org/techniques/T1558/003/) | Kerberoasting | Credential Access | - - - | [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-detect_pass_the_hash.md b/docs/_posts/2020-10-21-detect_pass_the_hash.md index 8d4aac8ad7..78c57ccf48 100644 --- a/docs/_posts/2020-10-21-detect_pass_the_hash.md +++ b/docs/_posts/2020-10-21-detect_pass_the_hash.md @@ -36,20 +36,13 @@ This search looks for specific authentication events from the Windows Security E - **ID**: 7cd8b9fa-6b0c-424f-92a6-9c5287a72f5f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - - | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md index ba600a41dd..e76ca72a1a 100644 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md @@ -35,17 +35,12 @@ This search looks for commands that the SNICat tool uses in the TLS SNI field. - **ID**: 82d06410-134c-11eb-adc1-0242ac120002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1041](https://attack.mitre.org/techniques/T1041/) | Exfiltration Over C2 Channel | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index 6a89855118..0745de75bc 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -48,28 +48,15 @@ By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organiz - **ID**: c3be767e-7959-44c5-8976-0e9c12a91ad2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - - - | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - - - | [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | - - | [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Credential Access, Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index fa8b8cf958..88ce44e879 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -49,28 +49,15 @@ By enabling Port Security on a Cisco switch you can restrict input to an interfa - **ID**: 2de3d5b8-a4fa-45c5-8540-6d071c194d24 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - - - | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - - - | [T1557](https://attack.mitre.org/techniques/T1557/) | Man-in-the-Middle | Credential Access, Collection | - - | [T1557.002](https://attack.mitre.org/techniques/T1557/002/) | ARP Cache Poisoning | Credential Access, Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 3d88c46829..b9b83cd2b9 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -41,20 +41,13 @@ Adversaries may abuse netbooting to load an unauthorized network device operatin - **ID**: cc590c66-f65f-48f2-986a-4797244762f8 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1542.005](https://attack.mitre.org/techniques/T1542/005/) | TFTP Boot | Defense Evasion, Persistence | - - - | [T1542](https://attack.mitre.org/techniques/T1542/) | Pre-OS Boot | Defense Evasion, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index eb08c79257..7717e3b39a 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -45,28 +45,15 @@ Adversaries may leverage traffic mirroring in order to automate data exfiltratio - **ID**: 42b3b753-5925-49c5-9742-36fa40a73990 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1200](https://attack.mitre.org/techniques/T1200/) | Hardware Additions | Initial Access | - - - | [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - - - | [T1498](https://attack.mitre.org/techniques/T1498/) | Network Denial of Service | Impact | - - | [T1020.001](https://attack.mitre.org/techniques/T1020/001/) | Traffic Duplication | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md b/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md index 3c171059e2..4f171eb2ae 100644 --- a/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md @@ -71,57 +71,22 @@ This detection indicates use of Mimikatz modules that facilitate Pass-the-Token - **ID**: 759a653f-cb92-40f9-94c9-ec4e47b0f709 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - | [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - | [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - - - | [T1556](https://attack.mitre.org/techniques/T1556/) | Modify Authentication Process | Credential Access, Defense Evasion, Persistence | - - - | [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md b/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md index 4a0e56a9b8..7b6b98d34d 100644 --- a/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md +++ b/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md @@ -69,57 +69,22 @@ Stolen credentials are applied by methods such as user impersonation, credential - **ID**: 270b482d-2af2-448f-9923-9cf005f61be4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - | [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - | [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - - - | [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - - - | [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md b/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md index e7d4bcd670..07aa83b362 100644 --- a/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md +++ b/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md @@ -49,37 +49,17 @@ This detection identifies use of DSInternals modules that verify password streng - **ID**: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - | [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | - - - | [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md b/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md index 00f86585a1..94eff803ce 100644 --- a/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md @@ -55,42 +55,19 @@ This detection identifies reconnaissance of credential stores and use of CryptoA - **ID**: 5facee5b-79e4-47ab-b0e6-c625acc0554f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - | [T1590.001](https://attack.mitre.org/techniques/T1590/001/) | Domain Properties | Reconnaissance | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1589.001](https://attack.mitre.org/techniques/T1589/001/) | Credentials | Reconnaissance | - - - | [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - - - | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1589](https://attack.mitre.org/techniques/T1589/) | Gather Victim Identity Information | Reconnaissance | - - | [T1590.003](https://attack.mitre.org/techniques/T1590/003/) | Network Trust Dependencies | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md b/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md index 09e1c70564..3ac365b857 100644 --- a/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md +++ b/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md @@ -40,25 +40,14 @@ This detection identifies illegal setting of credentials via DSInternals modules - **ID**: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md b/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md index 2347e3c426..cd2ab2a667 100644 --- a/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md @@ -40,25 +40,14 @@ This detection identifies illegal setting of credentials via Mimikatz modules. - **ID**: c8b84699-7652-4363-910f-efd1ca82f780 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md b/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md index 81a18c4bf3..af62b0c8a7 100644 --- a/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md +++ b/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md @@ -40,25 +40,14 @@ This detection identifies illegal setting of credentials via PowerSploit modules - **ID**: 07b2a501-f967-4ddc-9f56-2dce46dfce44 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md b/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md index 9bbc722120..5af3b06483 100644 --- a/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md +++ b/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md @@ -37,21 +37,13 @@ This detection identifies use of PowerSploit modules that facilitate access prob - **ID**: d405af5d-99f1-45af-8dfb-b8f98b764247 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md b/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md index f1cbbea968..dcb78bd2e0 100644 --- a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md @@ -41,25 +41,14 @@ This detection identifies use of Mimikatz modules for discovery of accounts and - **ID**: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - | [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md index 9b81a645a1..9cc7e70f23 100644 --- a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md @@ -41,25 +41,14 @@ This detection identifies access to PowerSploit modules that discover accounts, - **ID**: 63422f8e-766c-468f-8133-2ba6795e263b -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - | [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md index 31f2cc453c..d4de4ee378 100644 --- a/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md @@ -55,37 +55,17 @@ This detection identifies use of PowerSploit modules that discover opportunities - **ID**: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - | [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md index d3932a4390..76a6dc567c 100644 --- a/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md @@ -40,27 +40,15 @@ This detection identifies use of PowerSploit modules for assessment of presence - **ID**: 24b4e659-63a2-4e7b-89ac-87dd659c7110 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance | - - | [T1595.002](https://attack.mitre.org/techniques/T1595/002/) | Vulnerability Scanning | Reconnaissance | - - - | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - | [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md index e3be182368..c5beedeb39 100644 --- a/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md @@ -40,25 +40,14 @@ This detection identifies use of PowerSploit modules for assessment of privilege - **ID**: b9b4492c-2af8-449b-beb4-b1b78d963321 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md index e089ddcfca..4da6745a0e 100644 --- a/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md @@ -41,25 +41,14 @@ This detection identifies use of Mimikatz modules for discovery of process or se - **ID**: fc5c1cbd-7494-4314-aad2-458d6fd4fada -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - | [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md index ba92a97e33..59375d56c5 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md @@ -43,33 +43,16 @@ This detection identifies access to PowerSploit modules for reconnaissance and a - **ID**: db08ac40-ee14-43e9-9a75-dddd059ef812 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1199](https://attack.mitre.org/techniques/T1199/) | Trusted Relationship | Initial Access | - - - | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - | [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - - - | [T1591](https://attack.mitre.org/techniques/T1591/) | Gather Victim Org Information | Reconnaissance | - - - | [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md index f7382d9b31..caad968cb0 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md @@ -37,25 +37,14 @@ This detection identifies access to PowerSploit modules that discover computers, - **ID**: fe1c4c5a-09f3-4b43-8129-560a7f38a08b -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - | [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md index 81045d65ff..a20e16a7a3 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md @@ -31,17 +31,12 @@ This detection identifies use of Mimikatz modules for discovery of computers and - **ID**: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md index 60c222183b..797b33e0fe 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md @@ -55,48 +55,20 @@ This detection identifies access to PowerSploit modules that discover and access - **ID**: c1d33ad9-1727-4f9f-a474-4adbe4fed68a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1057](https://attack.mitre.org/techniques/T1057/) | Process Discovery | Discovery | - - - | [T1083](https://attack.mitre.org/techniques/T1083/) | File and Directory Discovery | Discovery | - - | [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance | - - - | [T1046](https://attack.mitre.org/techniques/T1046/) | Network Service Scanning | Discovery | - - - | [T1012](https://attack.mitre.org/techniques/T1012/) | Query Registry | Discovery | - - - | [T1007](https://attack.mitre.org/techniques/T1007/) | System Service Discovery | Discovery | - - - | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - | [T1518](https://attack.mitre.org/techniques/T1518/) | Software Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md index fdfa7dbc36..d934e558cc 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md @@ -37,25 +37,14 @@ This detection identifies use of Mimikatz modules for discovery and access to se - **ID**: 0243d37c-57c1-4182-bfd1-39b212255fc8 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1007](https://attack.mitre.org/techniques/T1007/) | System Service Discovery | Discovery | - - - | [T1046](https://attack.mitre.org/techniques/T1046/) | Network Service Scanning | Discovery | - - - | [T1057](https://attack.mitre.org/techniques/T1057/) | Process Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md index 105aa5a1a2..dad2d2b7cf 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md @@ -40,28 +40,15 @@ This detection identifies use of Mimikatz modules for discovery and access to ne - **ID**: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - | [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - - - | [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | - - | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md index 1dd26d3953..281a272fed 100644 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md @@ -40,28 +40,15 @@ This detection identifies access to PowerSploit modules that discover and access - **ID**: 6b7ca431-6b1e-4b40-9589-21cb368e369e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - | [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - - - | [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | - - | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md index 8ee1cbb36d..f6550553dc 100644 --- a/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md +++ b/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md @@ -40,28 +40,15 @@ This detection identifies access to PowerSploit modules for reconnaissance of co - **ID**: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - | [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - - - | [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | - - | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-ryuk_test_files_detected.md b/docs/_posts/2020-11-06-ryuk_test_files_detected.md index a8e275c55a..5af1c2efcf 100644 --- a/docs/_posts/2020-11-06-ryuk_test_files_detected.md +++ b/docs/_posts/2020-11-06-ryuk_test_files_detected.md @@ -33,17 +33,12 @@ The search looks for files that contain the key word *Ryuk* under any folder in - **ID**: 57d44d70-28d9-4ed1-acf5-1c80ae2bbce3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md b/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md index 01d6ca5922..ed9f736472 100644 --- a/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md +++ b/docs/_posts/2020-11-06-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md @@ -38,20 +38,13 @@ Monitor for changes of the ExecutionPolicy in the registry to the values "un - **ID**: c2590137-0b08-4985-9ec5-6ae23d92f63d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md index 36036ff03f..b7cb7afbc3 100644 --- a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md +++ b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md @@ -33,17 +33,12 @@ The search looks for a Windows Security Account Manager (SAM) was stopped via co - **ID**: 69c12d59-d951-431e-ab77-ec426b8d65e6 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-common_ransomware_extensions.md b/docs/_posts/2020-11-09-common_ransomware_extensions.md index 59282b91bd..3f7f61e507 100644 --- a/docs/_posts/2020-11-09-common_ransomware_extensions.md +++ b/docs/_posts/2020-11-09-common_ransomware_extensions.md @@ -34,17 +34,12 @@ The search looks for file modifications with extensions commonly used by Ransomw - **ID**: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-common_ransomware_notes.md b/docs/_posts/2020-11-09-common_ransomware_notes.md index 2b82394488..85050ace3a 100644 --- a/docs/_posts/2020-11-09-common_ransomware_notes.md +++ b/docs/_posts/2020-11-09-common_ransomware_notes.md @@ -34,17 +34,12 @@ The search looks for files created with names matching those typically used in r - **ID**: ada0f478-84a8-4641-a3f1-d82362d6bd71 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-deleting_shadow_copies.md b/docs/_posts/2020-11-09-deleting_shadow_copies.md index 4fa2a7d411..724c37f7c1 100644 --- a/docs/_posts/2020-11-09-deleting_shadow_copies.md +++ b/docs/_posts/2020-11-09-deleting_shadow_copies.md @@ -34,17 +34,12 @@ The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service - **ID**: b89919ed-ee5f-492c-b139-95dbb162039e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md index d451dcb538..8bd8e52246 100644 --- a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md +++ b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md @@ -42,20 +42,13 @@ This search identifies endpoints that have caused a relatively high number of ac - **ID**: c026e3dd-7e18-4abb-8f41-929e836efe74 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - | [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md index 3e16f69729..25ca5a431a 100644 --- a/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md +++ b/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md @@ -40,29 +40,15 @@ This detection identifies access to PowerSploit modules that enable illegaly acc - **ID**: 01fc7d91-eb0c-478e-8633-e4fa4904463a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - | [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - - - | [T1123](https://attack.mitre.org/techniques/T1123/) | Audio Capture | Collection | - - - | [T1563](https://attack.mitre.org/techniques/T1563/) | Remote Service Session Hijacking | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md index 0f0965c439..9568283bd1 100644 --- a/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md +++ b/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md @@ -31,17 +31,12 @@ This detection identifies access to PowerSploit modules that create accounts ill - **ID**: 20fba62a-fa5b-46cc-b39f-473fa248fee2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1585](https://attack.mitre.org/techniques/T1585/) | Establish Accounts | Resource Development | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md b/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md index 92cad1d9c9..edc669f977 100644 --- a/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md @@ -31,17 +31,12 @@ This detection identifies access to PowerSploit modules that delete event logs. - **ID**: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md b/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md index 8b8a0f9da1..9e8381931f 100644 --- a/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md +++ b/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md @@ -37,21 +37,13 @@ This detection identifies use of DSInternals modules that enable or disable acco - **ID**: 3e0f9962-9989-445f-878c-939443326b63 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md b/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md index f5f4410584..eb63aa6247 100644 --- a/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md +++ b/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md @@ -38,25 +38,14 @@ This detection identifies use of DSInternals modules for illegal management of A - **ID**: a587ca9f-c138-47b4-ba51-699f319b8cc5 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - | [T1207](https://attack.mitre.org/techniques/T1207/) | Rogue Domain Controller | Defense Evasion | - - - | [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md index 546fb5c689..d4cadf9daa 100644 --- a/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md +++ b/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md @@ -38,25 +38,14 @@ This detection identifies access to PowerSploit modules that enable illegal mana - **ID**: 75760c11-7d48-4968-b828-013b299e8f6d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - | [T1207](https://attack.mitre.org/techniques/T1207/) | Rogue Domain Controller | Defense Evasion | - - - | [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md index 065d22cf3f..2d415400a9 100644 --- a/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md +++ b/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md @@ -41,25 +41,14 @@ This detection identifies access to PowerSploit modules that illegaly elevate ge - **ID**: 88c10ee9-fe72-4bce-b343-5b129044b991 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - | [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md b/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md index 75c9ba6f52..efd858791c 100644 --- a/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md @@ -36,21 +36,13 @@ This detection identifies use of Mimikatz modules for illegal privilege elevatio - **ID**: 2f873b1f-6352-4844-b7b9-b419f09a42c7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md b/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md index a9e4fa03e1..398b0420e6 100644 --- a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md +++ b/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md @@ -38,25 +38,14 @@ This detection identifies use of Mimikatz modules for illegal control over servi - **ID**: aaf3adf1-73e1-4477-b4ee-3771898964f1 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - | [T1106](https://attack.mitre.org/techniques/T1106/) | Native API | Execution | - - - | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md index 21cfd4f0c7..921e1bcc2b 100644 --- a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md +++ b/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md @@ -38,25 +38,14 @@ This detection identifies access to PowerSploit modules that enable illegal cont - **ID**: 0e910e5b-309d-4bc3-8af2-0030c02aa353 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - | [T1106](https://attack.mitre.org/techniques/T1106/) | Native API | Execution | - - - | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md index a61dd05ba3..ddc198748b 100644 --- a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md +++ b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md @@ -36,17 +36,12 @@ This search looks for fast execution of processes used for system network config - **ID**: a51bfe1a-94f0-48cc-b1e4-16ae10145893 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1016](https://attack.mitre.org/techniques/T1016/) | System Network Configuration Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md index ac90a4c87a..93f21ce1e3 100644 --- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md +++ b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md @@ -37,20 +37,13 @@ This search looks for executions of cmd.exe spawned by a process that is often a - **ID**: dcfd6b40-42f9-469d-a433-2e53f7486664 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md index bd37924825..75ed902b0d 100644 --- a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md +++ b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md @@ -38,20 +38,13 @@ The search looks for modifications to registry keys that control the enforcement - **ID**: bbc644bc-37df-4e1a-9c88-ec9a53e2038c -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md index 413c3a875e..cdd0ec9671 100644 --- a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md +++ b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md @@ -37,20 +37,13 @@ This search looks for processes launched from files that have double extensions - **ID**: b06a555e-dce0-417d-a2eb-28a5d8d66ef7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md b/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md index c5cda8cf66..31b0b1539b 100644 --- a/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md +++ b/docs/_posts/2020-11-23-monitor_registry_keys_for_print_monitors.md @@ -38,20 +38,13 @@ This search looks for registry activity associated with modifications to the reg - **ID**: f5f6af30-7ba7-4295-bfe9-07de87c01bbc -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.010](https://attack.mitre.org/techniques/T1547/010/) | Port Monitors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md index d9df2335ab..3fd4bbfaec 100644 --- a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md +++ b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md @@ -39,20 +39,13 @@ This search detects the process execution and arguments required to silently cre - **ID**: 404620de-46d8-48b6-90cc-8a8d7b0876a3 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md index f692171044..660f4b51c8 100644 --- a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md +++ b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md @@ -41,20 +41,13 @@ The search looks for reg.exe modifying registry keys that define Windows service - **ID**: 8470d755-0c13-45b3-bd63-387a373c10cf -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1574.011](https://attack.mitre.org/techniques/T1574/011/) | Services Registry Permissions Weakness | Persistence, Privilege Escalation, Defense Evasion | - - - | [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md b/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md index c4e92bc51a..94b87e67a5 100644 --- a/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md +++ b/docs/_posts/2020-11-26-registry_keys_for_creating_shim_databases.md @@ -38,20 +38,13 @@ This search looks for registry activity associated with application compatibilit - **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md b/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md index 9755266ef9..c3acf010dd 100644 --- a/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md +++ b/docs/_posts/2020-11-27-registry_keys_used_for_privilege_escalation.md @@ -38,20 +38,13 @@ This search looks for modifications to registry keys that can be used to elevate - **ID**: c9f4b923-f8af-4155-b697-1354f5bcbc5e -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.012](https://attack.mitre.org/techniques/T1546/012/) | Image File Execution Options Injection | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-30-remote_process_instantiation_via_wmi.md b/docs/_posts/2020-11-30-remote_process_instantiation_via_wmi.md index a16369356b..9f93fb9491 100644 --- a/docs/_posts/2020-11-30-remote_process_instantiation_via_wmi.md +++ b/docs/_posts/2020-11-30-remote_process_instantiation_via_wmi.md @@ -34,17 +34,12 @@ This analytic identifies wmic.exe being launched with parameters to spawn a proc - **ID**: d25d2c3d-d9d8-40ec-8fdf-e86fe155a3da -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md b/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md index 28c39e8ff0..8309008aa1 100644 --- a/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md +++ b/docs/_posts/2020-11-30-rundll_loading_dll_by_ordinal.md @@ -37,20 +37,13 @@ This search looks for executing scripts with rundll32. Adversaries may abuse run - **ID**: 6c135f8d-5e60-454e-80b7-c56eed739833 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md index fb175569d8..e604aa47f1 100644 --- a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md +++ b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md @@ -41,20 +41,13 @@ This search looks for flags passed to schtasks.exe on the command-line that indi - **ID**: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-08-shim_database_file_creation.md b/docs/_posts/2020-12-08-shim_database_file_creation.md index 4a5e79531e..22b0bc12f7 100644 --- a/docs/_posts/2020-12-08-shim_database_file_creation.md +++ b/docs/_posts/2020-12-08-shim_database_file_creation.md @@ -38,20 +38,13 @@ This search looks for shim database files being written to default directories. - **ID**: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.011](https://attack.mitre.org/techniques/T1546/011/) | Application Shimming | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md index 2fe9af28f7..de194923f8 100644 --- a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md +++ b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md @@ -37,20 +37,13 @@ This search looks for process names that consist only of a single letter. - **ID**: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - | [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md index e712dc7b68..a58e775c13 100644 --- a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md +++ b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md @@ -39,20 +39,13 @@ During triage, review the parallel processes - what process moved the native Win - **ID**: a34aae96-ccf8-4aef-952c-3ea21444444d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-08-unusually_long_command_line.md b/docs/_posts/2020-12-08-unusually_long_command_line.md index d057cb5c29..9ec40893de 100644 --- a/docs/_posts/2020-12-08-unusually_long_command_line.md +++ b/docs/_posts/2020-12-08-unusually_long_command_line.md @@ -29,8 +29,6 @@ Command lines that are extremely long may be indicative of malicious activity on - **Author**: David Dorsey, Splunk - **ID**: c77162d3-f93c-45cc-80c8-22f6a4264e7f - - #### Search ``` diff --git a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md index e7666e1edf..4f49a205a3 100644 --- a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md +++ b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md @@ -43,20 +43,13 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons - **ID**: ad05aae6-3b2a-4f73-af97-57bd26cee3b9 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index 5d395afe9b..c6827e748c 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -35,17 +35,12 @@ The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost - **ID**: 701a8740-e8db-40df-9190-5516d3819787 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md index 4234cbb440..0696dab5f3 100644 --- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md +++ b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md @@ -37,20 +37,13 @@ This search detects the assignment of rights to accesss content from another mai - **ID**: b25d2973-303e-47c8-bacd-52b61604c6a7 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114.002](https://attack.mitre.org/techniques/T1114/002/) | Remote Email Collection | Collection | - - - | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index c03c3a30d6..8780db1ef1 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -38,20 +38,13 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir - **ID**: 7f398cfb-918d-41f4-8db8-2e2474e02222 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.001](https://attack.mitre.org/techniques/T1110/001/) | Password Guessing | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-o365_disable_mfa.md b/docs/_posts/2020-12-16-o365_disable_mfa.md index 91c9472a99..57f85575aa 100644 --- a/docs/_posts/2020-12-16-o365_disable_mfa.md +++ b/docs/_posts/2020-12-16-o365_disable_mfa.md @@ -36,17 +36,12 @@ This search detects when multi factor authentication has been disabled, what ent - **ID**: c783dd98-c703-4252-9e8a-f19d9f5c949e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1556](https://attack.mitre.org/techniques/T1556/) | Modify Authentication Process | Credential Access, Defense Evasion, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md b/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md index baa223ca04..63aa125114 100644 --- a/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md +++ b/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md @@ -34,17 +34,12 @@ This search detects when an excessive number of authentication failures occur th - **ID**: d441364c-349c-453b-b55f-12eccab67cf9 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-o365_pst_export_alert.md b/docs/_posts/2020-12-16-o365_pst_export_alert.md index 32c05ee1b0..2c54427f68 100644 --- a/docs/_posts/2020-12-16-o365_pst_export_alert.md +++ b/docs/_posts/2020-12-16-o365_pst_export_alert.md @@ -34,17 +34,12 @@ This search detects when a user has performed an Ediscovery search or exported a - **ID**: 5f694cc4-a678-4a60-9410-bffca1b647dc -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md index 16efc321b4..c672ad87fa 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md @@ -37,20 +37,13 @@ This search detects when an admin configured a forwarding rule for multiple mail - **ID**: 7f398cfb-918d-41f4-8db8-2e2474e02c28 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection | - - - | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md index 8e21f41e1e..c3bcc35ded 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md @@ -37,20 +37,13 @@ This search detects when multiple user configured a forwarding rule to the same - **ID**: f8dfe015-dbb3-4569-ba75-b13787e06aa4 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114.003](https://attack.mitre.org/techniques/T1114/003/) | Email Forwarding Rule | Collection | - - - | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-16-windows_adfind_exe.md b/docs/_posts/2020-12-16-windows_adfind_exe.md index 524fcc4571..922aa630ba 100644 --- a/docs/_posts/2020-12-16-windows_adfind_exe.md +++ b/docs/_posts/2020-12-16-windows_adfind_exe.md @@ -36,17 +36,12 @@ This search looks for the execution of `adfind.exe` with command-line arguments - **ID**: bd3b0187-189b-46c0-be45-f52da2bae67f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md b/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md index 7b78edc13a..b7659277e1 100644 --- a/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md +++ b/docs/_posts/2020-12-17-scheduled_task_deleted_or_created_via_cmd.md @@ -41,20 +41,13 @@ This search looks for flags passed to schtasks.exe on the command-line that indi - **ID**: d5af132c-7c17-439c-9d31-13d55340f36c -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md index cbe456a150..1cc4c23361 100644 --- a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md +++ b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md @@ -34,17 +34,12 @@ This search looks for flags passed to bcdedit.exe modifications to the built-in - **ID**: 809b31d2-5462-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md index 32dcbb1695..6d1cc8f8fc 100644 --- a/docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md @@ -31,17 +31,12 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th - **ID**: 14038953-e5f2-4daf-acff-5452062baf03 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2020-7-13-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-7-13-detect_prohibited_applications_spawning_cmd_exe.md index c732dc2bcc..8fc3bddbb0 100644 --- a/docs/_posts/2020-7-13-detect_prohibited_applications_spawning_cmd_exe.md +++ b/docs/_posts/2020-7-13-detect_prohibited_applications_spawning_cmd_exe.md @@ -31,17 +31,12 @@ This search looks for executions of cmd.exe spawned by a process that is often a - **ID**: c10a18cb-fd80-4ffa-a844-25026e0a0c94 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md index ca45356aa8..e9ab2af647 100644 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ b/docs/_posts/2021-01-06-supernova_webshell.md @@ -36,16 +36,12 @@ This search aims to detect the Supernova webshell used in the SUNBURST attack. - **ID**: 2ec08a09-9ff1-4dac-b59f-1efd57972ec1 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md index 5a41c70e81..2a4902a645 100644 --- a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md +++ b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md @@ -33,17 +33,12 @@ This search provides detection of KMS keys where action kms:Encrypt is accessibl - **ID**: c79c164f-4b21-4847-98f9-cf6a9f49179e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md index 1b43357116..d96b995aac 100644 --- a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md +++ b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md @@ -33,17 +33,12 @@ This search provides detection of users with KMS keys performing encryption spec - **ID**: 884a5f59-eec7-4f4a-948b-dbde18225fdc -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md index 34a01b9a81..2a54c40f44 100644 --- a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md +++ b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md @@ -37,20 +37,13 @@ The search looks for AWS CloudTrail events to detect if any network ACLs were cr - **ID**: ada0f478-84a8-4641-a3f1-d82362d6bd75 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md index f22c6bbc2a..9a21e7f898 100644 --- a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md +++ b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md @@ -37,20 +37,13 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo - **ID**: ada0f478-84a8-4641-a3f1-d82362d6fd75 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md index 584296b60b..b7e6445442 100644 --- a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md +++ b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md @@ -34,17 +34,12 @@ The following analytic identifies microsoft.workflow.compiler.exe usage. microso - **ID**: 9bbc62e8-55d8-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_path.md b/docs/_posts/2021-01-12-suspicious_msbuild_path.md index 1e5d9e6beb..4029491d6e 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_path.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_path.md @@ -43,27 +43,15 @@ The following analytic identifies msbuild.exe executing from a non-standard path - **ID**: f5198224-551c-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - | [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md index e1531ee1d6..9b4da1cd8b 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_rename.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_rename.md @@ -43,27 +43,15 @@ The following analytic identifies renamed instances of msbuild.exe executing. Ms - **ID**: 4006adac-5937-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - | [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md index 5e0163da94..5867c14ef4 100644 --- a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md +++ b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md @@ -37,20 +37,13 @@ The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavi - **ID**: a115fba6-5514-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - | [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md index 53d9bd4bc0..e8565ef470 100644 --- a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md +++ b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md @@ -37,20 +37,13 @@ The following analytic identifies child processes spawning from "mshta.exe& - **ID**: 60023bb6-5500-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md index 6e40ca2c9a..38b9eaee44 100644 --- a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md +++ b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md @@ -35,17 +35,12 @@ Malicious actors often abuse legitimate Dynamic DNS services to host malicious p - **ID**: c77162d3-f93c-45cc-80c8-22f6v5464g9f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1189](https://attack.mitre.org/techniques/T1189/) | Drive-by Compromise | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md index 4b1b4e93b8..854d49107d 100644 --- a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md +++ b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md @@ -38,20 +38,13 @@ This search looks for PowerShell processes launched with arguments that have cha - **ID**: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md index 606bd68b67..68dc0d7f6a 100644 --- a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md +++ b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md @@ -37,20 +37,13 @@ The following analytic identifies "rundll32.exe" execution with inline p - **ID**: 91c79f14-5b41-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md index ce99ef519e..d1e3075d5a 100644 --- a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md +++ b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md @@ -37,20 +37,13 @@ The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior - **ID**: 4d33a488-5b5f-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md index 4b4124c259..930090beea 100644 --- a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md +++ b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md @@ -34,17 +34,12 @@ This search looks for flags passed to wbadmin.exe (Windows Backup Administrator - **ID**: cd5aed7e-5cea-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md b/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md index 4f70093023..81a292997a 100644 --- a/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md +++ b/docs/_posts/2021-01-25-nltest_domain_trust_discovery.md @@ -34,17 +34,12 @@ This search looks for the execution of `nltest.exe` with command-line arguments - **ID**: c3e05466-5f22-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md index ff4e62590d..6b0fc473d1 100644 --- a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md +++ b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md @@ -36,17 +36,12 @@ This search provides specific SAML access from specific Service Provider, user a - **ID**: bbe23980-6019-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md index c1aa23bfcf..7bde52c878 100644 --- a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md +++ b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md @@ -36,17 +36,12 @@ This search provides detection of updates to SAML provider in AWS. Updates to SA - **ID**: 2f0604c6-6030-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md index dcfd834fe1..8ef6f8ee58 100644 --- a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md +++ b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md @@ -30,8 +30,6 @@ This search looks for arguments to certutil.exe indicating the manipulation or e - **Author**: Rod Soto, Splunk - **ID**: 337a46be-600f-11eb-ae93-0242ac130002 - - #### Search ``` diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md index dba9e3a747..afbac9d101 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md @@ -29,8 +29,6 @@ This search looks for a spike in number of of AWS security Hub alerts for an EC2 - **Author**: Bhavin Patel, Splunk - **ID**: 2a9b80d3-6340-4345-b5ad-290bf5d0d222 - - #### Search ``` diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md index f56633d6ce..03c7bb7c02 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md @@ -30,8 +30,6 @@ This search looks for a spike in number of of AWS security Hub alerts for an AWS - **Author**: Bhavin Patel, Splunk - **ID**: 2a9b80d3-6220-4345-b5ad-290bf5d0d222 - - #### Search ``` diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md index 6932d670c3..97373e7ad6 100644 --- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md +++ b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md @@ -37,20 +37,13 @@ This search detects the creation of a new Federation setting by alerting about a - **ID**: b2c81cc6-6040-11eb-ae93-0242ac130002 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-26-o365_added_service_principal.md b/docs/_posts/2021-01-26-o365_added_service_principal.md index 8906f28d27..fa28af7bf0 100644 --- a/docs/_posts/2021-01-26-o365_added_service_principal.md +++ b/docs/_posts/2021-01-26-o365_added_service_principal.md @@ -37,20 +37,13 @@ This search detects the creation of a new Federation setting by alerting about a - **ID**: 1668812a-6047-11eb-ae93-0242ac130002 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md index b67e5280db..4c2be76b37 100644 --- a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md +++ b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md @@ -36,17 +36,12 @@ This search detects accounts with high number of Single Sign ON (SSO) logon erro - **ID**: 8158ccc4-6038-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1556](https://attack.mitre.org/techniques/T1556/) | Modify Authentication Process | Credential Access, Defense Evasion, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md index 47f86945b8..3f65f890b9 100644 --- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md +++ b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md @@ -37,20 +37,13 @@ This search detects the addition of a new Federated domain. - **ID**: e155876a-6048-11eb-ae93-0242ac130002 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md index 28aadc1156..eb462bcaff 100644 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md @@ -36,17 +36,12 @@ This search detects the heap-based buffer overflow of sudoedit - **ID**: 93fbec4e-0375-440c-8db3-4508eca470c4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md index 42ac2599b9..e79359c829 100644 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md @@ -36,17 +36,12 @@ This search detects the heap-based buffer overflow of sudoedit - **ID**: 1de31d5d-8fa6-4ee0-af89-17069134118a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md index 624e0e4270..242491b96f 100644 --- a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md +++ b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md @@ -38,20 +38,13 @@ Upon investigating, look for network connections to remote destinations (interna - **ID**: 070e9b80-6252-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md index 03a6159246..703a6ee420 100644 --- a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md +++ b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md @@ -39,20 +39,13 @@ This technique uses "Install from Media" (IFM), which will extract a cop - **ID**: da63bc76-61ae-11eb-ae93-0242ac130002 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md index 99d130ad1e..3dea9f818b 100644 --- a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md +++ b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md @@ -37,20 +37,13 @@ Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using - **ID**: 62732736-6250-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md index 56a4e900ad..ec8ba68f93 100644 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md @@ -36,17 +36,12 @@ This search detects the heap-based buffer overflow of sudoedit - **ID**: 10f2bae0-bbe6-4984-808c-37dc1c67980d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md index 1828d60b45..41ad2bfca4 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md @@ -37,20 +37,13 @@ The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack - **ID**: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md index 3750409611..10eeac74e3 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md @@ -37,20 +37,13 @@ The following analytic identifies rundll32.exe loading setupapi.dll and iesetupa - **ID**: 61e7b44a-6088-4f26-b788-9a96ba13b37a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md index 86910920e3..7322ae0530 100644 --- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md +++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md @@ -37,20 +37,13 @@ The following analytic identifies rundll32.exe loading syssetup.dll by calling t - **ID**: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_rename.md b/docs/_posts/2021-02-04-suspicious_rundll32_rename.md index 93e6034168..7feb0fff2a 100644 --- a/docs/_posts/2021-02-04-suspicious_rundll32_rename.md +++ b/docs/_posts/2021-02-04-suspicious_rundll32_rename.md @@ -43,27 +43,15 @@ The following analytic identifies renamed instances of rundll32.exe executing. r - **ID**: 7360137f-abad-473e-8189-acbdaa34d114 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - - | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md index ae9f0b1ad5..a44c1b8dd3 100644 --- a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md +++ b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md @@ -37,20 +37,13 @@ The following analytic identifies rundll32.exe executing a DLL function name, St - **ID**: 9319dda5-73f2-4d43-a85a-67ce961bddb7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md index 6aef9b252f..d5fa159902 100644 --- a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md +++ b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md @@ -37,20 +37,13 @@ The following analytic identifies rundll32.exe using dllregisterserver on the co - **ID**: 8c00a385-9b86-4ac0-8932-c9ec3713b159 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md index 47d94bbf54..94bdc1682c 100644 --- a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md +++ b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md @@ -37,20 +37,13 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM - **ID**: 723716de-ee55-4cd4-9759-c44e7e55ba4b -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md index a6a3277bfc..9284228033 100644 --- a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md +++ b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md @@ -37,20 +37,13 @@ The following analytic identifies regasm.exe spawning a process. This particular - **ID**: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md index 04a345a573..41efbf06b0 100644 --- a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md +++ b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md @@ -37,20 +37,13 @@ The following analytic identifies regsvcs.exe spawning a process. This particula - **ID**: bc477b57-5c21-4ab6-9c33-668772e7f114 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md index 5f11c8d849..35629da22c 100644 --- a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md @@ -36,20 +36,13 @@ The following analytic identifies regasm.exe with a network connection to a publ - **ID**: 07921114-6db4-4e2e-ae58-3ea8a52ae93f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md index e655341ae9..22d4c3c869 100644 --- a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md @@ -36,20 +36,13 @@ The following analytic identifies Regsvcs.exe with a network connection to a pub - **ID**: e3e7a1c0-f2b9-445c-8493-f30a63522d1a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md index 44b94c113d..2538d9a159 100644 --- a/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md +++ b/docs/_posts/2021-02-22-aws_create_policy_version_to_allow_all_resources.md @@ -43,20 +43,13 @@ This search looks for AWS CloudTrail events where a user created a policy versio - **ID**: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md index 25826b16d7..02ab07ab69 100644 --- a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md +++ b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md @@ -35,17 +35,12 @@ Upon triage, review the process performing the named pipe. If it is explorer.exe - **ID**: 5876d429-0240-4709-8b93-ea8330b411b5 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index b376655e36..bc2345b9a7 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -36,17 +36,12 @@ The following analytic identifies the use of a curl contacting suspicious remote - **ID**: 3f613dc0-21f2-4063-93b1-5d3c15eef22f -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 215fd0fb3f..f069b0eba9 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -48,20 +48,13 @@ Upon triage, capture the property list file being written to disk and review for - **ID**: c3194009-e0eb-4f84-87a9-4070f8688f00 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index 06f81681f0..4d4eaca660 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -47,20 +47,13 @@ Upon triage, capture the property list file being written to disk and review for - **ID**: 20ba6c32-c733-4a32-b64e-2688cf231399 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543.001](https://attack.mitre.org/techniques/T1543/001/) | Launch Agent | Persistence, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md index 485690331a..193810be54 100644 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md @@ -36,17 +36,12 @@ The following analytic identifies the use of a SQLite3 querying the MacOS prefer - **ID**: e1997b2e-655f-4561-82fd-aeba8e1c1a86 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1074](https://attack.mitre.org/techniques/T1074/) | Data Staged | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-01-any_powershell_downloadfile.md b/docs/_posts/2021-03-01-any_powershell_downloadfile.md index ec5e041166..69c78af2bb 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadfile.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadfile.md @@ -37,20 +37,13 @@ The following analytic identifies the use of PowerShell downloading a file using - **ID**: 1a93b7ea-7af7-11eb-adb5-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-01-any_powershell_downloadstring.md b/docs/_posts/2021-03-01-any_powershell_downloadstring.md index 862dcfe4ce..85fb13423b 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadstring.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadstring.md @@ -37,20 +37,13 @@ The following analytic identifies the use of PowerShell downloading a file using - **ID**: 4d015ef2-7adf-11eb-95da-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-01-eventvwr_uac_bypass.md b/docs/_posts/2021-03-01-eventvwr_uac_bypass.md index 0f821b9c08..4aaef07cc9 100644 --- a/docs/_posts/2021-03-01-eventvwr_uac_bypass.md +++ b/docs/_posts/2021-03-01-eventvwr_uac_bypass.md @@ -40,20 +40,13 @@ The following search identifies Eventvwr bypass by identifying the registry modi - **ID**: 9cf8fe08-7ad8-11eb-9819-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md index f4004b1595..28a693764e 100644 --- a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md +++ b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md @@ -47,24 +47,14 @@ Upon triage, fodhelper.exe will have a child process and read access will occur - **ID**: 909f8fd8-7ac8-11eb-a1f3-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md index a472e6e09f..01746e5fc6 100644 --- a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md +++ b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md @@ -38,20 +38,13 @@ This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. - **ID**: 538d0152-7aaa-11eb-beaa-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md index 2cf6fa5de8..4bf1738202 100644 --- a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md +++ b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md @@ -42,20 +42,13 @@ The following detection identifies Scheduled Tasks registering (creating a new t - **ID**: 7feb7972-7ac3-11eb-bac8-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md index adfc31b7b1..701859e601 100644 --- a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md +++ b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md @@ -43,20 +43,13 @@ This search looks for AWS CloudTrail events where a user has set a default polic - **ID**: 2a9b80d3-6340-4345-11ad-212bf3d0dac4 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md index e0250bfbe0..cf7924714d 100644 --- a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md +++ b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md @@ -35,17 +35,12 @@ This detection identifies Microsoft Exchange Server's Unified Messaging serv - **ID**: f1126df0-7bd5-11eb-988f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md index 857c7572ab..6d50146c6f 100644 --- a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md +++ b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md @@ -37,20 +37,13 @@ The search looks for the Registry Key DisableAntiSpyware set to disable. This is - **ID**: 23150a40-9301-4195-b802-5bb4f43067fb -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md index a9e5a6c986..d5d0c79aa0 100644 --- a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md +++ b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md @@ -37,20 +37,13 @@ This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a - **ID**: 1a382c6c-7c2e-11eb-ac69-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-03-w3wp_spawning_shell.md b/docs/_posts/2021-03-03-w3wp_spawning_shell.md index f0dd43d531..e54683f195 100644 --- a/docs/_posts/2021-03-03-w3wp_spawning_shell.md +++ b/docs/_posts/2021-03-03-w3wp_spawning_shell.md @@ -40,20 +40,13 @@ This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe - **ID**: 0f03423c-7c6a-11eb-bc47-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - - | [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md b/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md index c7e5960522..25935d8d28 100644 --- a/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md +++ b/docs/_posts/2021-03-12-create_service_in_suspicious_file_path.md @@ -37,20 +37,13 @@ This detection is to identify a creation of "user mode service" where th - **ID**: 429141be-8311-11eb-adb6-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md index f2e861ced1..4883b91407 100644 --- a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md +++ b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md @@ -34,17 +34,12 @@ The following analytics identifies a big number of instance of ransomware notes - **ID**: eff7919a-8330-11eb-83f8-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md index 41f2cd461c..02e3b7d03b 100644 --- a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md +++ b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md @@ -34,17 +34,12 @@ The following analytics identifies the resizing of shadowstorage by ransomware m - **ID**: bc760ca6-8336-11eb-bcbb-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-16-high_file_deletion_frequency.md b/docs/_posts/2021-03-16-high_file_deletion_frequency.md index 8c6193bd77..f3325f9733 100644 --- a/docs/_posts/2021-03-16-high_file_deletion_frequency.md +++ b/docs/_posts/2021-03-16-high_file_deletion_frequency.md @@ -34,17 +34,12 @@ This search looks for high frequency of file deletion relative to process name a - **ID**: 45b125c4-866f-11eb-a95a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-16-high_process_termination_frequency.md b/docs/_posts/2021-03-16-high_process_termination_frequency.md index a370ee99aa..fabb549904 100644 --- a/docs/_posts/2021-03-16-high_process_termination_frequency.md +++ b/docs/_posts/2021-03-16-high_process_termination_frequency.md @@ -34,17 +34,12 @@ This analytics are designed to indentify a high frequency of process termination - **ID**: 17cd75b2-8666-11eb-9ab4-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1486](https://attack.mitre.org/techniques/T1486/) | Data Encrypted for Impact | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-17-clop_common_exec_parameter.md b/docs/_posts/2021-03-17-clop_common_exec_parameter.md index 531d88d5fe..c79332f301 100644 --- a/docs/_posts/2021-03-17-clop_common_exec_parameter.md +++ b/docs/_posts/2021-03-17-clop_common_exec_parameter.md @@ -34,17 +34,12 @@ The following analytics are designed to identifies some CLOP ransomware variant - **ID**: 5a8a2a72-8322-11eb-9ee9-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md index 617ded8261..be594dec68 100644 --- a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md +++ b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md @@ -35,17 +35,12 @@ This detection is to identify the common service name created by the CLOP ransom - **ID**: 07e08a12-870c-11eb-b5f9-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md b/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md index ea515239fb..3802c8db92 100644 --- a/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md +++ b/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md @@ -34,17 +34,12 @@ This detection is to identify a suspicious process that tries to delete the proc - **ID**: f7eda4bc-871c-11eb-b110-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md b/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md index 12ec1d545a..0d37bc30f6 100644 --- a/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md +++ b/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md @@ -34,17 +34,12 @@ Certutil.exe may download a file from a remote destination using `-urlcache`. Th - **ID**: 415b4306-8bfb-11eb-85c4-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md b/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md index b39751b2ca..3fe1151906 100644 --- a/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md +++ b/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md @@ -34,17 +34,12 @@ Certutil.exe may download a file from a remote destination using `-VerifyCtl`. T - **ID**: 801ad9e4-8bfb-11eb-8b31-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-23-certutil_with_decode_argument.md b/docs/_posts/2021-03-23-certutil_with_decode_argument.md index 8d48fad1e8..ed78d76ac5 100644 --- a/docs/_posts/2021-03-23-certutil_with_decode_argument.md +++ b/docs/_posts/2021-03-23-certutil_with_decode_argument.md @@ -34,17 +34,12 @@ CertUtil.exe may be used to `encode` and `decode` a file, including PE and scrip - **ID**: bfe94226-8c10-11eb-a4b3-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1140](https://attack.mitre.org/techniques/T1140/) | Deobfuscate/Decode Files or Information | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md index a409611792..12f3d22fc2 100644 --- a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md +++ b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md @@ -35,17 +35,12 @@ Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar - **ID**: 39e2605a-90d8-11eb-899e-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md index 92e9a2e464..c8b002eb02 100644 --- a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md +++ b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md @@ -40,24 +40,14 @@ The following query uses IAM events to track the success of a group being delete - **ID**: e776d06c-9267-11eb-819b-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069.003](https://attack.mitre.org/techniques/T1069/003/) | Cloud Groups | Discovery | - - - | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disable_registry_tool.md b/docs/_posts/2021-03-31-disable_registry_tool.md index e5c64fd1da..7654572442 100644 --- a/docs/_posts/2021-03-31-disable_registry_tool.md +++ b/docs/_posts/2021-03-31-disable_registry_tool.md @@ -37,20 +37,13 @@ This search identifies modification of registry to disable the regedit or regist - **ID**: cd2cf33c-9201-11eb-a10a-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disable_show_hidden_files.md b/docs/_posts/2021-03-31-disable_show_hidden_files.md index c49eab957a..48cea5c021 100644 --- a/docs/_posts/2021-03-31-disable_show_hidden_files.md +++ b/docs/_posts/2021-03-31-disable_show_hidden_files.md @@ -43,27 +43,15 @@ The following analytic is to identify a modification in the Windows registry to - **ID**: 6f3ccfa2-91fe-11eb-8f9b-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1564.001](https://attack.mitre.org/techniques/T1564/001/) | Hidden Files and Directories | Defense Evasion | - - | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1564](https://attack.mitre.org/techniques/T1564/) | Hide Artifacts | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md b/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md index f1ec8d8939..a3def9e6b6 100644 --- a/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md +++ b/docs/_posts/2021-03-31-disable_windows_behavior_monitoring.md @@ -37,20 +37,13 @@ This search is to identifies a modification in registry to disable the windows d - **ID**: 79439cae-9200-11eb-a4d3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md b/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md index 9a8d972372..9f271f62c4 100644 --- a/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md +++ b/docs/_posts/2021-03-31-disable_windows_smartscreen_protection.md @@ -37,20 +37,13 @@ The following search identifies a modification of registry to disable the smarts - **ID**: 664f0fd0-91ff-11eb-a56f-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_cmd_application.md b/docs/_posts/2021-03-31-disabling_cmd_application.md index 19acb5711c..f913337c3f 100644 --- a/docs/_posts/2021-03-31-disabling_cmd_application.md +++ b/docs/_posts/2021-03-31-disabling_cmd_application.md @@ -37,20 +37,13 @@ this search is to identify modification in registry to disable cmd prompt applic - **ID**: ff86077c-9212-11eb-a1e6-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_controlpanel.md b/docs/_posts/2021-03-31-disabling_controlpanel.md index f25fafb1f4..e81b1d2cc4 100644 --- a/docs/_posts/2021-03-31-disabling_controlpanel.md +++ b/docs/_posts/2021-03-31-disabling_controlpanel.md @@ -37,20 +37,13 @@ this search is to identify registry modification to disable control panel window - **ID**: 6ae0148e-9215-11eb-a94a-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md index 99d356e72b..0992711829 100644 --- a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md +++ b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md @@ -37,20 +37,13 @@ This search is to identifies suspicious firewall disabling using netsh applicati - **ID**: 6860a62c-9203-11eb-9e05-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md b/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md index 8b2eeff282..36c6fd5727 100644 --- a/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md +++ b/docs/_posts/2021-03-31-disabling_folderoptions_windows_feature.md @@ -37,20 +37,13 @@ This search is to identify registry modification to disable folder options featu - **ID**: 83776de4-921a-11eb-868a-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_norun_windows_app.md b/docs/_posts/2021-03-31-disabling_norun_windows_app.md index d9dc7f88b5..6860a52574 100644 --- a/docs/_posts/2021-03-31-disabling_norun_windows_app.md +++ b/docs/_posts/2021-03-31-disabling_norun_windows_app.md @@ -37,20 +37,13 @@ This search is to identify modification of registry to disable run application i - **ID**: de81bc46-9213-11eb-adc9-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md b/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md index f014bc9df2..e15984aab4 100644 --- a/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md +++ b/docs/_posts/2021-03-31-disabling_systemrestore_in_registry.md @@ -37,20 +37,13 @@ The following search identifies the modification of registry related in disablin - **ID**: f4f837e2-91fb-11eb-8bf6-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-disabling_task_manager.md b/docs/_posts/2021-03-31-disabling_task_manager.md index e02871bdc7..e183e9eb1f 100644 --- a/docs/_posts/2021-03-31-disabling_task_manager.md +++ b/docs/_posts/2021-03-31-disabling_task_manager.md @@ -37,20 +37,13 @@ This search is to identifies modification of registry to disable the task manage - **ID**: dac279bc-9202-11eb-b7fb-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-03-31-dsquery_domain_discovery.md b/docs/_posts/2021-03-31-dsquery_domain_discovery.md index b10ec2bdbc..9e63e051e5 100644 --- a/docs/_posts/2021-03-31-dsquery_domain_discovery.md +++ b/docs/_posts/2021-03-31-dsquery_domain_discovery.md @@ -39,17 +39,12 @@ In addition to trust discovery, review parallel processes for additional behavio - **ID**: cc316032-924a-11eb-91a2-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md index 9596e4051d..2eea0abdc3 100644 --- a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md +++ b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md @@ -37,21 +37,13 @@ The following detection identifies any malformed policy document exceptions with - **ID**: f19e09b0-9308-11eb-b7ec-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1580](https://attack.mitre.org/techniques/T1580/) | Cloud Infrastructure Discovery | Discovery | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-01-aws_iam_delete_policy.md b/docs/_posts/2021-04-01-aws_iam_delete_policy.md index c7cbdc3dc8..1e8f5ba590 100644 --- a/docs/_posts/2021-04-01-aws_iam_delete_policy.md +++ b/docs/_posts/2021-04-01-aws_iam_delete_policy.md @@ -34,17 +34,12 @@ The following detection identifes when a policy is deleted on AWS. This does not - **ID**: ec3a9362-92fe-11eb-99d0-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md index 8382f67e64..8f04a3412a 100644 --- a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md +++ b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md @@ -34,17 +34,12 @@ This detection identifies failure attempts to delete groups. We want to identify - **ID**: 723b861a-92eb-11eb-93b8-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-05-aws_iam_accessdenied_discovery_events.md b/docs/_posts/2021-04-05-aws_iam_accessdenied_discovery_events.md index 15dd4fa02b..b08af4bc7b 100644 --- a/docs/_posts/2021-04-05-aws_iam_accessdenied_discovery_events.md +++ b/docs/_posts/2021-04-05-aws_iam_accessdenied_discovery_events.md @@ -34,17 +34,12 @@ The following detection identifies excessive AccessDenied events within an hour - **ID**: 3e1f1568-9633-11eb-a69c-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1580](https://attack.mitre.org/techniques/T1580/) | Cloud Infrastructure Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md index fbc952f961..fe65a73c53 100644 --- a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md +++ b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md @@ -37,20 +37,13 @@ This detection is to identify the abuse the Windows SC.exe to execute malicious - **ID**: 8e204dfd-cae0-4ea8-a61d-e972a1ff2ff8 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md index dc3c170482..f10d36f8a6 100644 --- a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 3a91a212-98a9-11eb-b86a-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md index fec33917a0..9724035ee7 100644 --- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md +++ b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md @@ -44,20 +44,13 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or was it v - **ID**: 5d9c6eee-988c-11eb-8253-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-12-excel_spawning_powershell.md b/docs/_posts/2021-04-12-excel_spawning_powershell.md index 606b8fded6..98eccdf2bc 100644 --- a/docs/_posts/2021-04-12-excel_spawning_powershell.md +++ b/docs/_posts/2021-04-12-excel_spawning_powershell.md @@ -37,20 +37,13 @@ The following detection identifies Microsoft Excel spawning PowerShell. Typicall - **ID**: 42d40a22-9be3-11eb-8f08-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md index c8cd6162c0..2a77fde045 100644 --- a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md +++ b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md @@ -37,20 +37,13 @@ The following detection identifies Microsoft Excel spawning Windows Script Host - **ID**: 57fe880a-9be3-11eb-9bf3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md index 3efe529cd7..1af76b358c 100644 --- a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md +++ b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md @@ -44,20 +44,13 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or via Task - **ID**: 203ef0ea-9bd8-11eb-8201-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-12-winword_spawning_powershell.md b/docs/_posts/2021-04-12-winword_spawning_powershell.md index 9226c2ef1b..833fcce1ea 100644 --- a/docs/_posts/2021-04-12-winword_spawning_powershell.md +++ b/docs/_posts/2021-04-12-winword_spawning_powershell.md @@ -37,20 +37,13 @@ The following detection identifies Microsoft Word spawning PowerShell. Typically - **ID**: b2c950b8-9be2-11eb-8658-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md index ce7961ca1f..f85aa4e1c0 100644 --- a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md +++ b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md @@ -37,20 +37,13 @@ The following detection identifies Microsoft Winword.exe spawning Windows Script - **ID**: 637e1b5c-9be1-11eb-9c32-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md index 69c7e9929d..12f88934ae 100644 --- a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md +++ b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md @@ -34,17 +34,12 @@ This search looks for AWS CloudTrail events and analyse the amount of eventNames - **ID**: 1fdd164a-def8-4762-83a9-9ffe24e74d5a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md index c606f73a09..9199fafcfd 100644 --- a/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md +++ b/docs/_posts/2021-04-13-multiple_users_attempting_to_authenticate_using_explicit_credentials.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: e61918fa-9ca4-11eb-836c-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md index 7b82cbea4d..c07ec721e7 100644 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md +++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 7ed272a4-9c77-11eb-af22-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md index 9d79af631c..435e0b423f 100644 --- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md +++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 9015385a-9c84-11eb-bef2-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md index 9f4491d052..c19d77b18d 100644 --- a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md +++ b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 80f9d53e-9ca1-11eb-b0d6-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md index c8ddddbaf8..d90bc21632 100644 --- a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md +++ b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md @@ -37,20 +37,13 @@ this detection was designed to identifies suspicious spawned process of known MS - **ID**: 958751e4-9c5f-11eb-b103-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md index 6a9e227cb7..287c5a17a5 100644 --- a/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-14-multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 98f22d82-9d62-11eb-9fcf-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md index 3d84fc9c0c..86bf2c86bb 100644 --- a/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md +++ b/docs/_posts/2021-04-14-multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 001266a6-9d5b-11eb-829b-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md index 0b9fb12312..5c6677ae4d 100644 --- a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md +++ b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md @@ -37,20 +37,13 @@ this search detects a potential malicious office document that create schedule t - **ID**: cc8b7b74-9d0f-11eb-8342-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md index a2f1e15684..ae10e78683 100644 --- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md +++ b/docs/_posts/2021-04-14-office_document_executing_macro_code.md @@ -37,20 +37,13 @@ this detection was designed to identifies suspicious office documents that using - **ID**: b12c89bc-9d06-11eb-a592-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md index 3c655ff7a7..6405372d63 100644 --- a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md +++ b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md @@ -34,17 +34,12 @@ this search is to detect potential DNS exfiltration using nslookup application. - **ID**: 2452e632-9e0d-11eb-bacd-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md index 2a29ffe353..27be958446 100644 --- a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md +++ b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md @@ -40,20 +40,13 @@ The analytics returned fields allow analysts to investigate the event further by - **ID**: 57ad5a64-9df7-11eb-a290-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1110.003](https://attack.mitre.org/techniques/T1110/003/) | Password Spraying | Credential Access | - - - | [T1110](https://attack.mitre.org/techniques/T1110/) | Brute Force | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md index ac7f74d5a4..9d655b3227 100644 --- a/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-04-19-gpupdate_with_no_command_line_arguments_with_network.md @@ -35,17 +35,12 @@ The following analytic identifies gpupdate.exe with no command line arguments an - **ID**: 2c853856-a140-11eb-a5b5-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md index 56027d05df..29951455c8 100644 --- a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md +++ b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md @@ -35,17 +35,12 @@ this search is designed to detect suspicious powershell process that tries to in - **ID**: ec102cb2-a0f5-11eb-9b38-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md index 93563de5c8..397c5bf59a 100644 --- a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md +++ b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md @@ -36,17 +36,12 @@ The following query utilizes Windows Security EventCode 4698, `A scheduled task - **ID**: 523c2684-a101-11eb-916b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md index 3907db81c0..cff1be8d90 100644 --- a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md +++ b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md @@ -36,17 +36,12 @@ The following query utilizes Windows Security EventCode 4698, `A scheduled task - **ID**: 75b00fd8-a0ff-11eb-8b31-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md index 5b62051292..b0d6f0ec29 100644 --- a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md +++ b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md @@ -37,20 +37,13 @@ this search is designed to detect suspicious wermgr.exe process that tries to co - **ID**: ed313326-a0f9-11eb-a89c-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - - | [T1590.005](https://attack.mitre.org/techniques/T1590/005/) | IP Addresses | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md index d4f77b1293..d5d52bad41 100644 --- a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md +++ b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md @@ -34,17 +34,12 @@ this search is designed to detect potential malicious wermgr.exe process that dr - **ID**: ab3bcce0-a105-11eb-973c-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md index 7d4cd82e38..7acb4e5e1c 100644 --- a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md +++ b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md @@ -34,17 +34,12 @@ This search is designed to detect suspicious cmd and powershell process spawned - **ID**: e8fc95bc-a107-11eb-a978-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md index 222ea94c6c..098f5bab6f 100644 --- a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md +++ b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md @@ -34,17 +34,12 @@ This search is to detect potential DNS exfiltration using nslookup application. - **ID**: 0a69fdaa-a2b8-11eb-b16d-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md index 1a56252da5..45fedac671 100644 --- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md +++ b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md @@ -37,20 +37,13 @@ This search is designed to detect high frequency of archive files data exfiltrat - **ID**: 4477f3ea-a28f-11eb-b762-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | - - - | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md index 4abc931bdc..21b2169494 100644 --- a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md +++ b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md @@ -37,20 +37,13 @@ The following detection identifies a 7z.exe spawned from `Rundll32.exe` or `Dllh - **ID**: 9364ee8e-a39a-11eb-8f1d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - - - | [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md index d16f3f1136..4abff20229 100644 --- a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md +++ b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md @@ -37,20 +37,13 @@ The following detection identifies the latest behavior utilized by IcedID malwar - **ID**: c661f6be-a38c-11eb-be57-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md index 27cad93557..678272395a 100644 --- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md +++ b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md @@ -37,20 +37,13 @@ This search is to detect potential plain HTTP POST method data exfiltration. Thi - **ID**: e2b36208-a364-11eb-8909-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | - - - | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-22-winword_spawning_cmd.md b/docs/_posts/2021-04-22-winword_spawning_cmd.md index 652682b233..40f5237e93 100644 --- a/docs/_posts/2021-04-22-winword_spawning_cmd.md +++ b/docs/_posts/2021-04-22-winword_spawning_cmd.md @@ -37,20 +37,13 @@ The following detection identifies Microsoft Word spawning `cmd.exe`. Typically, - **ID**: 6fcbaedc-a37b-11eb-956b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-23-write_executable_in_smb_share.md b/docs/_posts/2021-04-23-write_executable_in_smb_share.md index e61f94346f..d47c383862 100644 --- a/docs/_posts/2021-04-23-write_executable_in_smb_share.md +++ b/docs/_posts/2021-04-23-write_executable_in_smb_share.md @@ -37,20 +37,13 @@ This search is to detect suspicious dropping or creating an executable file in k - **ID**: f63c34fe-a435-11eb-935a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md index 116e6485f2..ee60a92a88 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md +++ b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md @@ -37,20 +37,13 @@ The following detection identifies the latest behavior utilized by different mal - **ID**: e8c591f4-a6d7-11eb-8cf7-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-26-office_product_spawning_certutil.md b/docs/_posts/2021-04-26-office_product_spawning_certutil.md index dc211d137b..6bc4092e61 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_certutil.md +++ b/docs/_posts/2021-04-26-office_product_spawning_certutil.md @@ -37,20 +37,13 @@ The following detection identifies the latest behavior utilized by different mal - **ID**: 6925fe72-a6d5-11eb-9e17-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-26-office_product_spawning_mshta.md b/docs/_posts/2021-04-26-office_product_spawning_mshta.md index 329ebd1dc1..9495978135 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_mshta.md +++ b/docs/_posts/2021-04-26-office_product_spawning_mshta.md @@ -37,20 +37,13 @@ The following detection identifies the latest behavior utilized by different mal - **ID**: 6078fa20-a6d2-11eb-b662-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-26-trickbot_named_pipe.md b/docs/_posts/2021-04-26-trickbot_named_pipe.md index 5baa8b22fc..6ea9a73ab9 100644 --- a/docs/_posts/2021-04-26-trickbot_named_pipe.md +++ b/docs/_posts/2021-04-26-trickbot_named_pipe.md @@ -35,17 +35,12 @@ this search is to detect potential trickbot infection through the create/connect - **ID**: 1804b0a4-a682-11eb-8f68-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-29-icacls_deny_command.md b/docs/_posts/2021-04-29-icacls_deny_command.md index 8c8a6e7b13..8a622e3c87 100644 --- a/docs/_posts/2021-04-29-icacls_deny_command.md +++ b/docs/_posts/2021-04-29-icacls_deny_command.md @@ -34,17 +34,12 @@ This analytic identifies a potential adversary that changes the security permiss - **ID**: cf8d753e-a8fe-11eb-8f58-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md index 804033e5c5..83e9c14043 100644 --- a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md +++ b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md @@ -39,20 +39,13 @@ This analytic will detect suspicious driver loaded paths. This technique is comm - **ID**: f880acd4-a8f1-11eb-a53b-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-04-29-xmrig_driver_loaded.md b/docs/_posts/2021-04-29-xmrig_driver_loaded.md index f0e2841a4b..3be75e8a63 100644 --- a/docs/_posts/2021-04-29-xmrig_driver_loaded.md +++ b/docs/_posts/2021-04-29-xmrig_driver_loaded.md @@ -39,20 +39,13 @@ This analytic identifies XMRIG coinminer driver installation on the system. The - **ID**: 90080fa6-a8df-11eb-91e4-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-deleting_of_net_users.md b/docs/_posts/2021-05-04-deleting_of_net_users.md index 5514794d1e..3c43ef4dc1 100644 --- a/docs/_posts/2021-05-04-deleting_of_net_users.md +++ b/docs/_posts/2021-05-04-deleting_of_net_users.md @@ -34,17 +34,12 @@ This analytic will detect a suspicious net.exe/net1.exe command-line to delete a - **ID**: 1c8c6f66-acce-11eb-aafb-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-disabling_net_user_account.md b/docs/_posts/2021-05-04-disabling_net_user_account.md index a3908134f7..38a6582db0 100644 --- a/docs/_posts/2021-05-04-disabling_net_user_account.md +++ b/docs/_posts/2021-05-04-disabling_net_user_account.md @@ -34,17 +34,12 @@ This analytic will identify a suspicious command-line that disables a user accou - **ID**: c0325326-acd6-11eb-98c2-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md index 4590bc671b..a53b910269 100644 --- a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md +++ b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md @@ -34,17 +34,12 @@ This analytic will identify suspicious series of command-line to disable several - **ID**: 8fa2a0f0-acd9-11eb-8994-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md index 32aa5c4343..bf5fc580a6 100644 --- a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md +++ b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md @@ -34,17 +34,12 @@ This analytic identifies suspicious series of attempt to kill multiple services - **ID**: ae8d3f4a-acd7-11eb-8846-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md index 47b6262f29..6a953af2b0 100644 --- a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md +++ b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md @@ -37,20 +37,13 @@ This analytic identifies excessive usage of `taskkill.exe` application. This app - **ID**: fe5bca48-accb-11eb-a67c-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-icacls_grant_command.md b/docs/_posts/2021-05-04-icacls_grant_command.md index d4b9916548..45f89caa83 100644 --- a/docs/_posts/2021-05-04-icacls_grant_command.md +++ b/docs/_posts/2021-05-04-icacls_grant_command.md @@ -34,17 +34,12 @@ This analytic identifies potential adversaries that modify the security permissi - **ID**: b1b1e316-accc-11eb-a9b4-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md b/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md index c5e6ddb06c..f3790387f2 100644 --- a/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md +++ b/docs/_posts/2021-05-04-modify_acl_permission_to_files_or_folder.md @@ -34,17 +34,12 @@ This analytic identifies suspicious modification of ACL permission to a files or - **ID**: 7e8458cc-acca-11eb-9e3f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md index 30073fb236..68617f7186 100644 --- a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md +++ b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md @@ -37,20 +37,13 @@ The following analytic identifies the use of `wmic.exe` using `delete` to remove - **ID**: 5ffaa42c-acdb-11eb-9ad3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md b/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md index 3bc9b0bc68..d038c42131 100644 --- a/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md +++ b/docs/_posts/2021-05-05-disable_windows_app_hotkeys.md @@ -37,20 +37,13 @@ This analytic detects a suspicious registry modification to disable Windows hotk - **ID**: 1490f224-ad8b-11eb-8c4f-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md b/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md index 0b9f74bfbb..61843b7689 100644 --- a/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md +++ b/docs/_posts/2021-05-05-hide_user_account_from_sign-in_screen.md @@ -37,20 +37,13 @@ This analytic identifies a suspicious registry modification to hide a user accou - **ID**: 834ba832-ad89-11eb-937d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-05-suspicious_process_file_path.md b/docs/_posts/2021-05-05-suspicious_process_file_path.md index 8306a930a7..8376499edc 100644 --- a/docs/_posts/2021-05-05-suspicious_process_file_path.md +++ b/docs/_posts/2021-05-05-suspicious_process_file_path.md @@ -35,17 +35,12 @@ The following analytic will detect a suspicious process running in a file path w - **ID**: 9be25988-ad82-11eb-a14f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-06-download_files_using_telegram.md b/docs/_posts/2021-05-06-download_files_using_telegram.md index e6fa172d73..9c9d171d6e 100644 --- a/docs/_posts/2021-05-06-download_files_using_telegram.md +++ b/docs/_posts/2021-05-06-download_files_using_telegram.md @@ -34,17 +34,12 @@ The following analytic will identify a suspicious download by the Telegram appli - **ID**: 58194e28-ae5e-11eb-8912-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md index acafcea64f..7d2fded03e 100644 --- a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md +++ b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md @@ -34,17 +34,12 @@ This analytic will detect a suspicious Telegram process enumerating all network - **ID**: fcd74532-ae54-11eb-a5ab-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md index da46831902..f086f7b525 100644 --- a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md +++ b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md @@ -34,17 +34,12 @@ This analytic identifies excessive usage of `net.exe` or `net1.exe` within a buc - **ID**: 45e52536-ae42-11eb-b5c6-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1531](https://attack.mitre.org/techniques/T1531/) | Account Access Removal | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md index 36f850fae5..01979b72fd 100644 --- a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md +++ b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md @@ -34,17 +34,12 @@ This analytic will identify suspicious executable or scripts (known file extensi - **ID**: a7e3f0f0-ae42-11eb-b245-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md index 6ecd7d516c..4e3b8732d5 100644 --- a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md +++ b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md @@ -34,17 +34,12 @@ The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` o - **ID**: 0bdf6092-af17-11eb-939a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md index ecb4dc60df..112b7e03d7 100644 --- a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md +++ b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md @@ -36,17 +36,12 @@ This analytic identifies an on demand run of a Windows Schedule Task through she - **ID**: bb37061e-af1f-11eb-a159-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md index c160656865..24aab81a10 100644 --- a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md +++ b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md @@ -34,17 +34,12 @@ This following analytic detects PowerShell command to delete shadow copy using t - **ID**: 5ee2bcd0-b2ff-11eb-bb34-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md index 75b6bf0a1f..5fa0fef3c4 100644 --- a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md +++ b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md @@ -37,20 +37,13 @@ This analytic detects a potential process using COM Object like CMLUA or CMSTPLU - **ID**: f87b5062-b405-11eb-a889-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-13-detect_rclone_command-line_usage.md b/docs/_posts/2021-05-13-detect_rclone_command-line_usage.md index 47ddec1cd2..bcfd2c7c9d 100644 --- a/docs/_posts/2021-05-13-detect_rclone_command-line_usage.md +++ b/docs/_posts/2021-05-13-detect_rclone_command-line_usage.md @@ -34,17 +34,12 @@ This analytic identifies commonly used command-line arguments used by `rclone.ex - **ID**: 32e0baea-b3f1-11eb-a2ce-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-13-slui_runas_elevated.md b/docs/_posts/2021-05-13-slui_runas_elevated.md index 7670f672ef..518e3e5ba8 100644 --- a/docs/_posts/2021-05-13-slui_runas_elevated.md +++ b/docs/_posts/2021-05-13-slui_runas_elevated.md @@ -39,20 +39,13 @@ The following analytic identifies the Microsoft Software Licensing User Interfac - **ID**: 8d124810-b3e4-11eb-96c7-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-13-slui_spawning_a_process.md b/docs/_posts/2021-05-13-slui_spawning_a_process.md index 175baed703..3df0c69249 100644 --- a/docs/_posts/2021-05-13-slui_spawning_a_process.md +++ b/docs/_posts/2021-05-13-slui_spawning_a_process.md @@ -39,20 +39,13 @@ The following analytic identifies the Microsoft Software Licensing User Interfac - **ID**: 879c4330-b3e0-11eb-b1b1-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-18-services_escalate_exe.md b/docs/_posts/2021-05-18-services_escalate_exe.md index 37eed579cc..1c77ab43c9 100644 --- a/docs/_posts/2021-05-18-services_escalate_exe.md +++ b/docs/_posts/2021-05-18-services_escalate_exe.md @@ -36,17 +36,12 @@ The following analytic identifies the use of `svc-exe` with Cobalt Strike. The b - **ID**: c448488c-b7ec-11eb-8253-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md index a5d2d249cc..d51dc22219 100644 --- a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md +++ b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md @@ -37,20 +37,13 @@ The following analytic identifies suspicious PowerShell command to allow inbound - **ID**: a5d85486-b89c-11eb-8267-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md b/docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md index b6f1bb2c85..b07ad7e7bf 100644 --- a/docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md +++ b/docs/_posts/2021-05-19-enable_rdp_in_other_port_number.md @@ -34,17 +34,12 @@ This search is to detect a modification to registry to enable rdp to a machine w - **ID**: 99495452-b899-11eb-96dc-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md index 52e9f11371..286ebc99ec 100644 --- a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md +++ b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md @@ -37,20 +37,13 @@ This search is to detect known mailsniper.ps1 functions executed in a machine. T - **ID**: a36972c8-b894-11eb-9f78-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1114](https://attack.mitre.org/techniques/T1114/) | Email Collection | Collection | - - | [T1114.001](https://attack.mitre.org/techniques/T1114/001/) | Local Email Collection | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md index d4773461eb..3c5fd5d696 100644 --- a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md +++ b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md @@ -46,27 +46,15 @@ This analytic identifies a common behavior by Cobalt Strike and other frameworks - **ID**: eb277ba0-b96b-11eb-b00e-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.003](https://attack.mitre.org/techniques/T1059/003/) | Windows Command Shell | Execution | - - | [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-20-rare_parent-child_process_relationship.md b/docs/_posts/2021-05-20-rare_parent-child_process_relationship.md index 1f34acc093..7ba0c8ede5 100644 --- a/docs/_posts/2021-05-20-rare_parent-child_process_relationship.md +++ b/docs/_posts/2021-05-20-rare_parent-child_process_relationship.md @@ -43,29 +43,15 @@ An attacker may use LOLBAS tools spawned from vulnerable applications not typica - **ID**: cf090c78-bcc6-11eb-8529-0242ac130003 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1203](https://attack.mitre.org/techniques/T1203/) | Exploitation for Client Execution | Execution | - - - | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - | [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - - - | [T1072](https://attack.mitre.org/techniques/T1072/) | Software Deployment Tools | Execution, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md index 2ad028fde7..8c2fd21a75 100644 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md @@ -39,17 +39,12 @@ The following analytic identifies suspicious processes spawning from WinRM (wsmp - **ID**: a081836a-ba4d-11eb-8593-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md index b4b19e68fb..57bd7eb248 100644 --- a/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md +++ b/docs/_posts/2021-05-26-allow_inbound_traffic_by_firewall_rule_registry.md @@ -37,20 +37,13 @@ This analytic detects a potential suspicious modification of firewall rule regis - **ID**: 0a46537c-be02-11eb-92ca-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021.001](https://attack.mitre.org/techniques/T1021/001/) | Remote Desktop Protocol | Lateral Movement | - - - | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md index 67b1c906ef..0938ee257d 100644 --- a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md +++ b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md @@ -37,20 +37,13 @@ This analytic detects a potential usage of secretsdump.py tool for dumping crede - **ID**: 5672819c-be09-11eb-bbfb-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md index 38a9919529..e35b125ee6 100644 --- a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md +++ b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md @@ -52,37 +52,18 @@ SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. Shar - **ID**: 42b4b438-beed-11eb-ba1d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-05-27-detect_sharphound_usage.md b/docs/_posts/2021-05-27-detect_sharphound_usage.md index 1be2235867..55a23964bb 100644 --- a/docs/_posts/2021-05-27-detect_sharphound_usage.md +++ b/docs/_posts/2021-05-27-detect_sharphound_usage.md @@ -52,37 +52,18 @@ The following analytic identifies SharpHound binary usage by using the original - **ID**: dd04b29a-beed-11eb-87bc-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md index cece372f23..9017f3613b 100644 --- a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md +++ b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md @@ -52,37 +52,18 @@ The following analytic identifies the common command-line argument used by Azure - **ID**: 26f02e96-c300-11eb-b611-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md index 09e60af837..e50e963e2c 100644 --- a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md +++ b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md @@ -52,37 +52,18 @@ The following analytic is similar to SharpHound file modifications, but this ins - **ID**: 1c34549e-c31b-11eb-996b-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md index 66f2f44b28..86a62de55f 100644 --- a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md +++ b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md @@ -52,37 +52,18 @@ The following analytic identifies common command-line arguments used by SharpHou - **ID**: a0bdd2f6-c2ff-11eb-b918-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-02-conti_common_exec_parameter.md b/docs/_posts/2021-06-02-conti_common_exec_parameter.md index a07bffd30d..cccfbc7e64 100644 --- a/docs/_posts/2021-06-02-conti_common_exec_parameter.md +++ b/docs/_posts/2021-06-02-conti_common_exec_parameter.md @@ -34,17 +34,12 @@ This search detects the suspicious commandline argument of revil ransomware to e - **ID**: 624919bc-c382-11eb-adcc-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-02-modification_of_wallpaper.md b/docs/_posts/2021-06-02-modification_of_wallpaper.md index 9a56f5f2e4..a250adf05f 100644 --- a/docs/_posts/2021-06-02-modification_of_wallpaper.md +++ b/docs/_posts/2021-06-02-modification_of_wallpaper.md @@ -34,17 +34,12 @@ This analytic identifies suspicious modification of registry to deface or change - **ID**: accb0712-c381-11eb-8e5b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1491](https://attack.mitre.org/techniques/T1491/) | Defacement | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-02-revil_common_exec_parameter.md b/docs/_posts/2021-06-02-revil_common_exec_parameter.md index d99a0d9568..174e1d912b 100644 --- a/docs/_posts/2021-06-02-revil_common_exec_parameter.md +++ b/docs/_posts/2021-06-02-revil_common_exec_parameter.md @@ -34,17 +34,12 @@ This analytic identifies suspicious commandline parameter that are commonly used - **ID**: 85facebe-c382-11eb-9c3e-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-02-revil_registry_entry.md b/docs/_posts/2021-06-02-revil_registry_entry.md index ca6f5c20e3..296f28d985 100644 --- a/docs/_posts/2021-06-02-revil_registry_entry.md +++ b/docs/_posts/2021-06-02-revil_registry_entry.md @@ -34,17 +34,12 @@ This analytic identifies suspicious modification in registry entry to keep some - **ID**: e3d3f57a-c381-11eb-9e35-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md index 11faf0cf81..d9531d2c54 100644 --- a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md +++ b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md @@ -37,20 +37,13 @@ this search is designed to detect potential malicious process loading COM object - **ID**: 9d911ce0-c3be-11eb-b177-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md b/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md index cfa6441a1c..bdc5339311 100644 --- a/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md +++ b/docs/_posts/2021-06-03-excessive_number_of_distinct_processes_created_in_windows_temp_folder.md @@ -34,17 +34,12 @@ This analytic will identify suspicious series of process executions. We have ob - **ID**: 23587b6a-c479-11eb-b671-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md index 22b22dd023..934d6ab89f 100644 --- a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md +++ b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md @@ -34,17 +34,12 @@ This search detects a suspicioous termination of known services killed by ransom - **ID**: 3070f8e0-c528-11eb-b2a0-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md index a51c19bcb0..39153e200b 100644 --- a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md +++ b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md @@ -34,17 +34,12 @@ This detection targets behaviors observed in post exploit kits like Meterpreter - **ID**: f443dac2-c7cf-11eb-ab51-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md index aa6d76b0c8..62e2f9bb68 100644 --- a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md +++ b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md @@ -43,24 +43,14 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: a26d9db4-c883-11eb-9d75-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md index e0e20e7e09..e196957b91 100644 --- a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md +++ b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md @@ -43,24 +43,14 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 8acbc04c-c882-11eb-b060-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - | [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md index ad5108d0f9..497a202370 100644 --- a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md +++ b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md @@ -38,20 +38,13 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: bc1dc6b8-c954-11eb-bade-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md index c7978172a8..ea71135905 100644 --- a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md +++ b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md @@ -35,17 +35,12 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 8148c29c-c952-11eb-9255-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md index da22b5a9d6..bd6bcb5df5 100644 --- a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md +++ b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md @@ -35,17 +35,12 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: a21e3484-c94d-11eb-b55b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-allow_operation_with_consent_admin.md b/docs/_posts/2021-06-10-allow_operation_with_consent_admin.md index b2477cec69..18ecfa7d29 100644 --- a/docs/_posts/2021-06-10-allow_operation_with_consent_admin.md +++ b/docs/_posts/2021-06-10-allow_operation_with_consent_admin.md @@ -35,17 +35,12 @@ This analytic identifies a potential privilege escalation attempt to perform mal - **ID**: 7de17d7a-c9d8-11eb-a812-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md index ef49835f3c..d1d6f54c08 100644 --- a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md +++ b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md @@ -37,20 +37,13 @@ this search is to detect execution of `cipher.exe` to clear the unallocated sect - **ID**: cd80a6ac-c9d9-11eb-8839-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - - - | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md index 2077e0112e..12b4cb78b2 100644 --- a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md +++ b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md @@ -37,20 +37,13 @@ This search is to detect execution of wevtutil.exe to disable logs. This techniq - **ID**: 236e7c8e-c9d9-11eb-a824-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md index 803154aab2..c0426c27d1 100644 --- a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md +++ b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md @@ -34,17 +34,12 @@ This search is to detect a modification of file or directory permission using ta - **ID**: fa7ca5c6-c9d8-11eb-bce9-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md index f3cffb99a0..6f3bc51e07 100644 --- a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md +++ b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md @@ -36,20 +36,13 @@ The following analytic identifies suspicious PowerShell script execution via Eve - **ID**: 637557ec-ca08-11eb-bd0a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - - | [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-powershell_domain_enumeration.md b/docs/_posts/2021-06-10-powershell_domain_enumeration.md index 726747cd5b..b376a076d4 100644 --- a/docs/_posts/2021-06-10-powershell_domain_enumeration.md +++ b/docs/_posts/2021-06-10-powershell_domain_enumeration.md @@ -38,20 +38,13 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: e1866ce2-ca22-11eb-8e44-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md index 83a444bedf..9c165b5b93 100644 --- a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md +++ b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_system_reflection_assembly.md @@ -38,20 +38,13 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 85bc3f30-ca28-11eb-bd21-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md index 366f2591ab..0a761f892d 100644 --- a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md +++ b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md @@ -36,20 +36,13 @@ The following analytic identifies suspicious PowerShell script execution via Eve - **ID**: 0d718b52-c9f1-11eb-bc61-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md b/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md index b260651dc5..5d23293597 100644 --- a/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md +++ b/docs/_posts/2021-06-10-powershell_using_memory_as_backing_store.md @@ -33,17 +33,12 @@ The following analytic identifies suspicious PowerShell script execution via Eve - **ID**: c396a0c4-c9f2-11eb-b4f5-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1140](https://attack.mitre.org/techniques/T1140/) | Deobfuscate/Decode Files or Information | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md index 358cfb89ca..ae4501c5bc 100644 --- a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md +++ b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md @@ -34,17 +34,12 @@ This search is to detect a suspicious bcdedit.exe execution to ignore all failur - **ID**: 7742aa92-c9d9-11eb-bbfc-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md b/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md index 426c7c0f68..98d71f1dd5 100644 --- a/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md +++ b/docs/_posts/2021-06-10-recon_avproduct_through_pwh_or_wmi.md @@ -33,17 +33,12 @@ The following analytic identifies suspicious PowerShell script execution via Eve - **ID**: 28077620-c9f6-11eb-8785-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-recon_using_wmi_class.md b/docs/_posts/2021-06-10-recon_using_wmi_class.md index 511930f6e7..9127a3fe10 100644 --- a/docs/_posts/2021-06-10-recon_using_wmi_class.md +++ b/docs/_posts/2021-06-10-recon_using_wmi_class.md @@ -33,17 +33,12 @@ The following analytic identifies suspicious PowerShell via EventCode 4104, wher - **ID**: 018c1972-ca07-11eb-9473-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md b/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md index 7716f518ba..70ecbe4764 100644 --- a/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md +++ b/docs/_posts/2021-06-10-start_up_during_safe_mode_boot.md @@ -39,20 +39,13 @@ This search is to detect a modification or registry add to the safeboot registry - **ID**: c6149154-c9d8-11eb-9da7-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md b/docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md index c539ee8d2b..65da2cf9c7 100644 --- a/docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md +++ b/docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md @@ -32,17 +32,12 @@ This analytic identifies a potential adversary that changes the security permiss - **ID**: b76eae28-cd25-11eb-9c92-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md b/docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md index 0f981e24e0..0e89f0a286 100644 --- a/docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md +++ b/docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md @@ -32,17 +32,12 @@ This analytic identifies potential adversaries that modify the security permissi - **ID**: c6da561a-cd29-11eb-ae65-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md index 7483ea4574..666397e307 100644 --- a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md +++ b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md @@ -33,17 +33,12 @@ The following analytic identifies suspicious PowerShell script execution via Eve - **ID**: b5cd5526-cce7-11eb-b3bd-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md b/docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md index 8b4031c047..b6e1d9193a 100644 --- a/docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md +++ b/docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md @@ -32,17 +32,12 @@ This analytic identifies suspicious modification of ACL permission to a files or - **ID**: 9ae9a48a-cdbe-11eb-875a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1222](https://attack.mitre.org/techniques/T1222/) | File and Directory Permissions Modification | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md index 1a4f0bea2e..0166da02e3 100644 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md +++ b/docs/_posts/2021-06-15-wevtutil_usage_to_clear_logs.md @@ -35,20 +35,13 @@ The wevtutil.exe application is the windows event log utility. This searches for - **ID**: 5438113c-cdd9-11eb-93b8-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md index 96ffa13fad..63f3639362 100644 --- a/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md +++ b/docs/_posts/2021-06-15-wevtutil_usage_to_disable_logs.md @@ -35,20 +35,13 @@ This search is to detect execution of wevtutil.exe to disable logs. This techniq - **ID**: a4bdc944-cdd9-11eb-ac97-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md index 1de8111295..9d015993d7 100644 --- a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md +++ b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md @@ -43,20 +43,13 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons - **ID**: 01d9a0c2-cece-11eb-ab46-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.003](https://attack.mitre.org/techniques/T1546/003/) | Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md index e740afd3be..4e8e03bcf5 100644 --- a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md +++ b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md @@ -36,20 +36,13 @@ The following analytic utilizes Windows Event ID 1100 to identify when Windows e - **ID**: 2b85aa3d-f5f6-4c2e-a081-a09f6e1c2e40 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-18-attempt_to_delete_services.md b/docs/_posts/2021-06-18-attempt_to_delete_services.md index 2ac84e45c5..40bb29f64f 100644 --- a/docs/_posts/2021-06-18-attempt_to_delete_services.md +++ b/docs/_posts/2021-06-18-attempt_to_delete_services.md @@ -32,17 +32,12 @@ This analytic identifies suspicious series of attempt to kill multiple services - **ID**: a0c8c292-d01a-11eb-aa18-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-18-attempt_to_disable_services.md b/docs/_posts/2021-06-18-attempt_to_disable_services.md index 925fe89c7e..4870b387ae 100644 --- a/docs/_posts/2021-06-18-attempt_to_disable_services.md +++ b/docs/_posts/2021-06-18-attempt_to_disable_services.md @@ -32,17 +32,12 @@ This analytic will identify suspicious series of command-line to disable several - **ID**: afb31de4-d023-11eb-98d5-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md b/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md index 117419d49d..95832ca7c5 100644 --- a/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md +++ b/docs/_posts/2021-06-21-attacker_tools_on_endpoint.md @@ -45,28 +45,15 @@ This search looks for execution of commonly used attacker tools on an endpoint. - **ID**: a51bfe1a-94f0-48cc-b4e4-16a110145893 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036.005](https://attack.mitre.org/techniques/T1036/005/) | Match Legitimate Name or Location | Defense Evasion | - - - | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - | [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-21-delete_a_net_user.md b/docs/_posts/2021-06-21-delete_a_net_user.md index baa5b3ca15..c3396931c8 100644 --- a/docs/_posts/2021-06-21-delete_a_net_user.md +++ b/docs/_posts/2021-06-21-delete_a_net_user.md @@ -32,17 +32,12 @@ This analytic will detect a suspicious net.exe/net1.exe command-line to delete a - **ID**: 8776d79c-d26e-11eb-9a56-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-21-disable_net_user_account.md b/docs/_posts/2021-06-21-disable_net_user_account.md index 2e7eec8f25..feb522991e 100644 --- a/docs/_posts/2021-06-21-disable_net_user_account.md +++ b/docs/_posts/2021-06-21-disable_net_user_account.md @@ -32,17 +32,12 @@ This analytic will identify a suspicious command-line that disables a user accou - **ID**: ba858b08-d26c-11eb-af9b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-21-resize_shadowstorage_volume.md b/docs/_posts/2021-06-21-resize_shadowstorage_volume.md index 41da3d1c77..2f1751b01b 100644 --- a/docs/_posts/2021-06-21-resize_shadowstorage_volume.md +++ b/docs/_posts/2021-06-21-resize_shadowstorage_volume.md @@ -32,17 +32,12 @@ The following analytics identifies the resizing of shadowstorage by ransomware m - **ID**: dbc30554-d27e-11eb-9e5e-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-22-disable_amsi_through_registry.md b/docs/_posts/2021-06-22-disable_amsi_through_registry.md index 97d77d5db0..516eea1762 100644 --- a/docs/_posts/2021-06-22-disable_amsi_through_registry.md +++ b/docs/_posts/2021-06-22-disable_amsi_through_registry.md @@ -37,20 +37,13 @@ this search is to identify modification in registry to disable AMSI windows feat - **ID**: 9c27ec42-d338-11eb-9044-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-22-disable_etw_through_registry.md b/docs/_posts/2021-06-22-disable_etw_through_registry.md index 08cadb7c0f..ec4d576640 100644 --- a/docs/_posts/2021-06-22-disable_etw_through_registry.md +++ b/docs/_posts/2021-06-22-disable_etw_through_registry.md @@ -37,20 +37,13 @@ this search is to identify modification in registry to disable ETW windows featu - **ID**: f0eacfa4-d33f-11eb-8f9d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md index fe0f0bfdbc..042e756f54 100644 --- a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md +++ b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md @@ -37,20 +37,13 @@ This analytic will identify suspicious process of cscript.exe where it tries to - **ID**: dc64d064-d346-11eb-8588-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md index 2f8caebced..2fcd1f065e 100644 --- a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md +++ b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md @@ -37,20 +37,13 @@ This search is to detect a suspicious enabling of smb1protocol through "powe - **ID**: afed80b2-d34b-11eb-a952-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - - | [T1027.005](https://attack.mitre.org/techniques/T1027/005/) | Indicator Removal from Tools | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md index 5ce6e73586..3dddca03ad 100644 --- a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md +++ b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md @@ -37,20 +37,13 @@ This search is to detect a suspicious commandline designed to delete files or di - **ID**: ba570b3a-d356-11eb-8358-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - - - | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md index 43dd1e4233..acba616849 100644 --- a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md @@ -37,20 +37,13 @@ This search is to detect a suspicious modification of firewall to allow file and - **ID**: ce27646e-d411-11eb-8a00-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md index c422c8d179..82a388d4cd 100644 --- a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md +++ b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md @@ -37,20 +37,13 @@ This search is to detect a suspicious modification to the firewall to allow netw - **ID**: ccd6a38c-d40b-11eb-85a5-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md index 17886f3ae8..2bedeb5ed9 100644 --- a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md +++ b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md @@ -37,20 +37,13 @@ This search is to detect a suspicious excessive usage of sc.exe in a host machin - **ID**: cb6b339e-d4c6-11eb-a026-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md index 0d73410d67..0202c6e7da 100644 --- a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md +++ b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md @@ -37,20 +37,13 @@ This detection targets behaviors observed when threat actors have used sc.exe to - **ID**: 77592bec-d5cc-11eb-9e60-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md index 6a8a3eb757..d78f6c1a54 100644 --- a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md +++ b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md @@ -43,20 +43,13 @@ During triage, isolate the endpoint and review for source of exploitation. Captu - **ID**: 313681a2-da8e-11eb-adad-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md index 60257f25e7..62f2f1b2f6 100644 --- a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md +++ b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md @@ -44,20 +44,13 @@ During triage, isolate the endpoint and review for source of exploitation. Captu - **ID**: 1adc9548-da7c-11eb-8f13-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-sdclt_uac_bypass.md b/docs/_posts/2021-07-01-sdclt_uac_bypass.md index e747dd8544..ce870b7b5f 100644 --- a/docs/_posts/2021-07-01-sdclt_uac_bypass.md +++ b/docs/_posts/2021-07-01-sdclt_uac_bypass.md @@ -39,20 +39,13 @@ This search is to detect a suspicious sdclt.exe registry modification. This tech - **ID**: d71efbf6-da63-11eb-8c6e-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md b/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md index 99354c16fc..1cb609d116 100644 --- a/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md +++ b/docs/_posts/2021-07-01-silentcleanup_uac_bypass.md @@ -39,20 +39,13 @@ This search is to detect a suspicious modification of registry that may related - **ID**: 56d7cfcc-da63-11eb-92d4-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md index d45dd0243e..73af555a26 100644 --- a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md +++ b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md @@ -40,20 +40,13 @@ The following analytic identifies a suspicious child process, `rundll32.exe`, wi - **ID**: 15d905f6-da6b-11eb-ab82-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md index ebcd4f8e1d..796cde5622 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md @@ -40,20 +40,13 @@ This search is to detect suspicious loading of dll in specific path relative to - **ID**: a5e451f8-da81-11eb-b245-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md index 7f9c8baefd..b68ca4de1d 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md @@ -35,17 +35,12 @@ This analytic identifies a suspicious behavior related to PrintNightmare, or CVE - **ID**: 799b606e-da81-11eb-93f8-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md index 37c6cd2af3..e796770edd 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md @@ -40,20 +40,13 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This - **ID**: d5bf5cf2-da71-11eb-92c2-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md index 5d372ff96b..0b30d16fe2 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md @@ -40,20 +40,13 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This - **ID**: 347fd388-da87-11eb-836d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-01-wsreset_uac_bypass.md b/docs/_posts/2021-07-01-wsreset_uac_bypass.md index 686ebf2a93..47fe703732 100644 --- a/docs/_posts/2021-07-01-wsreset_uac_bypass.md +++ b/docs/_posts/2021-07-01-wsreset_uac_bypass.md @@ -39,20 +39,13 @@ This search is to detect a suspicious modification of registry related to UAC by - **ID**: 8b5901bc-da63-11eb-be43-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md index c98bea3bc2..a6a2b52344 100644 --- a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md +++ b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md @@ -41,20 +41,13 @@ This search is to detect a suspicious creation of msmpeng.exe or mpsvc.dll in no - **ID**: 8bb3f280-dd9b-11eb-84d5-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1574.002](https://attack.mitre.org/techniques/T1574/002/) | DLL Side-Loading | Persistence, Privilege Escalation, Defense Evasion | - - - | [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md index 0bdbdf88c6..f9bb3d8b25 100644 --- a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md +++ b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md @@ -37,20 +37,13 @@ This search is to identifies a modification in registry to disable the windows d - **ID**: c148a894-dd93-11eb-bf2a-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.001](https://attack.mitre.org/techniques/T1562/001/) | Disable or Modify Tools | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-12-net_profiler_uac_bypass.md b/docs/_posts/2021-07-12-net_profiler_uac_bypass.md index 1217a00a34..923e947293 100644 --- a/docs/_posts/2021-07-12-net_profiler_uac_bypass.md +++ b/docs/_posts/2021-07-12-net_profiler_uac_bypass.md @@ -39,20 +39,13 @@ This search is to detect modification of registry to bypass UAC windows feature. - **ID**: 0252ca80-e30d-11eb-8aa3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md index d45c9345ff..c67e52c209 100644 --- a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md +++ b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md @@ -39,20 +39,13 @@ This search is to detect a suspicious loaded unsigned dll by MMC.exe application - **ID**: 7f04349c-e30d-11eb-bc7f-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md index f13fd8ac0d..e75a0233fb 100644 --- a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md +++ b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md @@ -43,20 +43,13 @@ This search looks for cloud compute instances created by users who have not crea - **ID**: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1078.004](https://attack.mitre.org/techniques/T1078/004/) | Cloud Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - | [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-aws_createaccesskey.md b/docs/_posts/2021-07-19-aws_createaccesskey.md index bc173e0572..83a1dd228a 100644 --- a/docs/_posts/2021-07-19-aws_createaccesskey.md +++ b/docs/_posts/2021-07-19-aws_createaccesskey.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events where a user A who has already permi - **ID**: 2a9b80d3-6340-4345-11ad-212bf3d0d111 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-aws_createloginprofile.md b/docs/_posts/2021-07-19-aws_createloginprofile.md index a91625c452..e0b0fe5e8a 100644 --- a/docs/_posts/2021-07-19-aws_createloginprofile.md +++ b/docs/_posts/2021-07-19-aws_createloginprofile.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events where a user A(victim A) creates a l - **ID**: 2a9b80d3-6340-4345-11ad-212bf444d111 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-aws_updateloginprofile.md b/docs/_posts/2021-07-19-aws_updateloginprofile.md index 0723962462..e62a95a0ef 100644 --- a/docs/_posts/2021-07-19-aws_updateloginprofile.md +++ b/docs/_posts/2021-07-19-aws_updateloginprofile.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events where a user A who has already permi - **ID**: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.003](https://attack.mitre.org/techniques/T1136/003/) | Cloud Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md index 933f071927..92b205556d 100644 --- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md +++ b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md @@ -34,17 +34,12 @@ This search looks for AWS CloudTrail events where a user has created an open/pub - **ID**: 2a9b80d3-6340-4345-b5ad-290bf3d0dac4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md index c69f5856f2..8b4e79ad3a 100644 --- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md +++ b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md @@ -34,17 +34,12 @@ This search looks for AWS CloudTrail events where a user has created an open/pub - **ID**: 39c61d09-8b30-4154-922b-2d0a694ecc22 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1530](https://attack.mitre.org/techniques/T1530/) | Data from Cloud Storage Object | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md index 0872a5a05e..6bc296474b 100644 --- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md +++ b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md @@ -37,20 +37,13 @@ This search is to detect a suspicious mshta.exe process that spawn rundll32 or r - **ID**: 4aa5d062-e893-11eb-9eb2-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md index f859b5a7ab..cd96098209 100644 --- a/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md +++ b/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md @@ -37,20 +37,13 @@ This search detects newly added IP addresses/CIDR blocks to the list of MFA Trus - **ID**: c783dd98-c703-4252-9e8a-f19d9f66949e -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.007](https://attack.mitre.org/techniques/T1562/007/) | Disable or Modify Cloud Firewall | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md index 0332183491..e4c00775aa 100644 --- a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md +++ b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md @@ -37,20 +37,13 @@ this search is to detect a suspicious office product process that spawn cmd chil - **ID**: b8b19420-e892-11eb-9244-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md index ba52160ed9..b50e21b777 100644 --- a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md +++ b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md @@ -34,17 +34,12 @@ The following analytic utilizes AWS CloudTrail events to identify when an EC2 sn - **ID**: 2a9b80d3-6340-4345-b5ad-290bf3d222c4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1537](https://attack.mitre.org/techniques/T1537/) | Transfer Data to Cloud Account | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md index 5fffc2990a..cddf0ac6a6 100644 --- a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md +++ b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md @@ -39,20 +39,13 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 9251299c-ea5b-11eb-a8de-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md index 0ccafdc26a..db64ba0866 100644 --- a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md +++ b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md @@ -38,20 +38,13 @@ The following analytic identifies access to SAM, SYSTEM or SECURITY databases - **ID**: 57551656-ebdb-11eb-afdf-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md index ac0e89d349..b5d170e6c0 100644 --- a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md +++ b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md @@ -35,17 +35,12 @@ This analytic identifies the suspicious Remote Thread execution of rundll32.exe - **ID**: f8a22586-ee2d-11eb-a193-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-26-rundll32_dnsquery.md b/docs/_posts/2021-07-26-rundll32_dnsquery.md index a60438ed36..6aea1f38c7 100644 --- a/docs/_posts/2021-07-26-rundll32_dnsquery.md +++ b/docs/_posts/2021-07-26-rundll32_dnsquery.md @@ -37,20 +37,13 @@ This search is to detect a suspicious rundll32.exe process having a http connect - **ID**: f1483f5e-ee29-11eb-9d23-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md index 80b2627202..e74cf8aa78 100644 --- a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md +++ b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md @@ -37,20 +37,13 @@ This search is to detect a suspicious rundll32 process that drops executable (.e - **ID**: 6338266a-ee2a-11eb-bf68-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md index 20dc89d115..db7c871ee3 100644 --- a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md +++ b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md @@ -37,20 +37,13 @@ This search is to detect a suspicious rundll32.exe commandline to execute dll fi - **ID**: bed761f8-ee29-11eb-8bf3-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md index f98966bc0d..e0be90b1f3 100644 --- a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md +++ b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md @@ -37,20 +37,13 @@ This search is to detect a suspicious rundll32.exe process with plugininit param - **ID**: 92d51712-ee29-11eb-b1ae-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-27-chcp_command_execution.md b/docs/_posts/2021-07-27-chcp_command_execution.md index f6966757ff..8eb0c270b8 100644 --- a/docs/_posts/2021-07-27-chcp_command_execution.md +++ b/docs/_posts/2021-07-27-chcp_command_execution.md @@ -34,17 +34,12 @@ This search is to detect execution of chcp.exe application. this utility is used - **ID**: 21d236ec-eec1-11eb-b23e-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md b/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md index 8c07f19b92..f0eda3b09a 100644 --- a/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md +++ b/docs/_posts/2021-07-27-suspicious_icedid_regsvr32_cmdline.md @@ -37,20 +37,13 @@ this search is to detect a suspicious regsvr32 commandline "-s" to execu - **ID**: c9ef7dc4-eeaf-11eb-b2b6-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md index 7b891505e2..31a0732d57 100644 --- a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md +++ b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md @@ -35,17 +35,12 @@ This analytic identifies the suspicious Remote Thread execution of rundll32.exe - **ID**: 2dbeee3a-f067-11eb-96c0-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-30-drop_icedid_license_dat.md b/docs/_posts/2021-07-30-drop_icedid_license_dat.md index 16772e39fc..072a9890a7 100644 --- a/docs/_posts/2021-07-30-drop_icedid_license_dat.md +++ b/docs/_posts/2021-07-30-drop_icedid_license_dat.md @@ -37,20 +37,13 @@ This search is to detect dropping a suspicious file named as "license.dat - **ID**: b7a045fc-f14a-11eb-8e79-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - | [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md index 277ddc306f..4b0cb97100 100644 --- a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md +++ b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md @@ -37,20 +37,13 @@ This search is to detect a suspicious file creation namely passff.tar and cookie - **ID**: 0db4da70-f14b-11eb-8043-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - - - | [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md index 88c5c9d6f5..b2c235d9cb 100644 --- a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md +++ b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md @@ -37,20 +37,13 @@ this detection was designed to identifies suspicious spawned process of known MS - **ID**: 2d9fc90c-f11f-11eb-9300-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md index 328cac0ff6..0a3279bb93 100644 --- a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md +++ b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md @@ -34,17 +34,12 @@ This search is to detect a suspicious file creation of sqlite3.dll in %temp% fol - **ID**: 0f216a38-f45f-11eb-b09c-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1005](https://attack.mitre.org/techniques/T1005/) | Data from Local System | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md index 1fc40935e3..7e2782872d 100644 --- a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md +++ b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md @@ -35,17 +35,12 @@ This search is to detect suspicious process injection in command shell. This tec - **ID**: 10399c1e-f51e-11eb-b920-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md index 196a8bb219..426bc0866e 100644 --- a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md +++ b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md @@ -37,20 +37,13 @@ This search is to detect a suspicious un-installation of application using msiex - **ID**: 1fca2b28-f922-11eb-b2dd-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218.007](https://attack.mitre.org/techniques/T1218/007/) | Msiexec | Defense Evasion | - - - | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-10-powershell_execute_com_object.md b/docs/_posts/2021-08-10-powershell_execute_com_object.md index 5eb67f3dce..17b39281aa 100644 --- a/docs/_posts/2021-08-10-powershell_execute_com_object.md +++ b/docs/_posts/2021-08-10-powershell_execute_com_object.md @@ -39,20 +39,13 @@ This search is to detect a COM CLSID execution through powershell. This techniqu - **ID**: 65711630-f9bf-11eb-8d72-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.015](https://attack.mitre.org/techniques/T1546/015/) | Component Object Model Hijacking | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-11-fsutil_zeroing_file.md b/docs/_posts/2021-08-11-fsutil_zeroing_file.md index 3339661254..3a4c4bda35 100644 --- a/docs/_posts/2021-08-11-fsutil_zeroing_file.md +++ b/docs/_posts/2021-08-11-fsutil_zeroing_file.md @@ -34,17 +34,12 @@ This search is to detect a suspicious fsutil process to zeroing a target file. T - **ID**: 4e5e024e-fabb-11eb-8b8f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md index e7fe91d48b..e32fd41c4d 100644 --- a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md +++ b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md @@ -37,20 +37,13 @@ This search is to detect a possible uac bypass using the colorui.dll COM Object. - **ID**: 2bcccd20-fc2b-11eb-8d22-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.003](https://attack.mitre.org/techniques/T1218/003/) | CMSTP | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md index edfaf5703c..ce0b0c86f0 100644 --- a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md +++ b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md @@ -37,20 +37,13 @@ This search is to detect suspicious google drive or google docs files shared out - **ID**: f6ee02d6-fea0-11eb-b2c2-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1567.002](https://attack.mitre.org/techniques/T1567/002/) | Exfiltration to Cloud Storage | Exfiltration | - - - | [T1567](https://attack.mitre.org/techniques/T1567/) | Exfiltration Over Web Service | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md index bf058a9361..721d49921a 100644 --- a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md +++ b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md @@ -37,20 +37,13 @@ This search is to detect a suspicious attachment file extension in Gsuite email - **ID**: 6d663014-fe92-11eb-ab07-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md index 4e8803c2a7..6c23e6c59a 100644 --- a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md +++ b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md @@ -37,20 +37,13 @@ This search is to detect a suspicious 7z process with commandline pointing to SM - **ID**: 01d29b48-ff6f-11eb-b81e-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - - - | [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md index d00ceb0abe..7120f6303d 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( - **ID**: 62721bd2-1d82-4623-b6e6-aac170014423 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md index e886bdc87d..a5018ec09b 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( - **ID**: cbc95e44-7c22-443f-88fd-0424478f5589 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md index fd615fa432..32a47d34d1 100644 --- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md +++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( - **ID**: 0b80e2c8-c746-4ddb-89eb-9efd892220cf -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md index ae36a4c6a4..25e4e32cff 100644 --- a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md +++ b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md @@ -37,20 +37,13 @@ This search is to detect a suspicious outbound e-mail from internal email to ext - **ID**: dc4dc3a8-ff54-11eb-8bf7-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | - - - | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-18-esentutl_sam_copy.md b/docs/_posts/2021-08-18-esentutl_sam_copy.md index 9c0744b98f..8f790ca5ea 100644 --- a/docs/_posts/2021-08-18-esentutl_sam_copy.md +++ b/docs/_posts/2021-08-18-esentutl_sam_copy.md @@ -38,20 +38,13 @@ The following analytic identifies the process - `esentutl.exe` - being used to c - **ID**: d372f928-ce4f-11eb-a762-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-18-powershell_4104_hunting.md b/docs/_posts/2021-08-18-powershell_4104_hunting.md index 4a595d4c1f..eaee6525d6 100644 --- a/docs/_posts/2021-08-18-powershell_4104_hunting.md +++ b/docs/_posts/2021-08-18-powershell_4104_hunting.md @@ -36,20 +36,13 @@ The following Hunting analytic assists with identifying suspicious PowerShell ex - **ID**: d6f2b006-0041-11ec-8885-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md index 1d47e4f495..6319d20285 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( - **ID**: d4c4d4eb-3994-41ca-a25e-a82d64e125bb -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md index b4593205a8..ce7f2a0314 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md @@ -37,20 +37,13 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( - **ID**: 300688e4-365c-4486-a065-7c884462b31d -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md index 6266eb4fc1..91fbf7baab 100644 --- a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md +++ b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md @@ -37,20 +37,13 @@ This search is to detect a gsuite email contains suspicious subject having known - **ID**: 8ef3971e-00f2-11ec-b54f-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md index 3438a0b3d2..8576f2dd5c 100644 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md @@ -33,8 +33,6 @@ The following analytic identifies cleartext protocols at risk of leaking sensiti - **Author**: Rico Valdez, Splunk - **ID**: 6923cd64-17a0-453c-b945-81ac2d8c6db9 - - #### Search ``` diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md index 6723ab8912..fb78d04402 100644 --- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md +++ b/docs/_posts/2021-08-20-github_commit_changes_in_master.md @@ -34,17 +34,12 @@ This search is to detect a pushed or commit to master or main branch. This is to - **ID**: c9d2bfe2-019f-11ec-a8eb-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1199](https://attack.mitre.org/techniques/T1199/) | Trusted Relationship | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md index 58cac9b04a..5cf7b51eae 100644 --- a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md +++ b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md @@ -34,17 +34,12 @@ This search uses the Kubernetes logs from a nginx ingress controller to detect l - **ID**: 0f83244b-425b-4528-83db-7a88c5f66e48 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1212](https://attack.mitre.org/techniques/T1212/) | Exploitation for Credential Access | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md index a9556eea49..1b62585549 100644 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md +++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 85fae8fa-0427-11ec-8b78-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md index 5c04ef6247..a0e6886a01 100644 --- a/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 2e891cbe-0426-11ec-9c9c-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md index e4a0f79f8c..7f2c74a775 100644 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md +++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: b44f6ac6-0429-11ec-87e9-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md index ba50bb8b60..27cfa64f82 100644 --- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md +++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 640b0eda-0429-11ec-accd-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md index 20078adf3d..6dc0ecc249 100644 --- a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md +++ b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md @@ -37,20 +37,13 @@ This analytics is to detect a gmail containing a link that are known to be abuse - **ID**: 8630aa22-042b-11ec-af39-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md index 7c99ae6328..009b6ef6ff 100644 --- a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md +++ b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md @@ -37,20 +37,13 @@ This search is to detect a shared file in google drive with suspicious file name - **ID**: 07eed200-03f5-11ec-98fb-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md index 3d3e16bff6..4f4c88d125 100644 --- a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md +++ b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md @@ -34,17 +34,12 @@ This search uses the Kubernetes logs from a nginx ingress controller to detect r - **ID**: fc5531ae-62fd-4de6-9c36-b4afdae8ca95 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1212](https://attack.mitre.org/techniques/T1212/) | Exploitation for Credential Access | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md index 4a216e8864..bee6aea97d 100644 --- a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md +++ b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: de7fcadc-04f3-11ec-a241-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md index 4ac5335948..a97f5695a6 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen - **ID**: b1a8ce04-04c2-11ec-bea7-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md index c99de38d92..f4fca616aa 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li - **ID**: 98f6a534-04c2-11ec-96b2-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md index ceec1b034e..fcc2a2519e 100644 --- a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md +++ b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments - **ID**: 383572e0-04c5-11ec-bdcc-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md index 0d34068afe..2644ba1f75 100644 --- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md +++ b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md @@ -34,17 +34,12 @@ This analytic identifies Get-DomainTrust from PowerView in order to gather domai - **ID**: 4fa7f846-054a-11ec-a836-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md index fd365dc0df..6ea90bb50e 100644 --- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md @@ -35,17 +35,12 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 89275e7e-0548-11ec-bf75-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell.md b/docs/_posts/2021-08-24-get_aduser_with_powershell.md index a76e462a76..e0f1d42494 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 0b6ee3f4-04e3-11ec-a87d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md index 49234b8a5b..42aa4d0599 100644 --- a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 21432e40-04f4-11ec-b7e6-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md index 3bbf5616e1..add4534706 100644 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md +++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 9a5a41d6-04e7-11ec-923c-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md index 9d5376d111..903819a992 100644 --- a/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 61994268-04f4-11ec-865c-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md index 7bddb6c1f5..c3c38f7a78 100644 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md +++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 22d3b118-04df-11ec-8fa3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md index 0d0eb83e8f..4ca3134843 100644 --- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md +++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: fabd364e-04f3-11ec-b34b-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md index a78825c9b4..04644ac574 100644 --- a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md +++ b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md @@ -34,17 +34,12 @@ This search uses the Kubernetes logs from Splunk Connect from Kubernetes to dete - **ID**: 4890cd6b-0112-4974-a272-c5c153aee551 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1526](https://attack.mitre.org/techniques/T1526/) | Cloud Service Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md index c7e84c3c82..f508da5875 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 089c862f-5f83-49b5-b1c8-7e4ff66560c7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md index fdd3062f75..9da320091d 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `net.exe` with command-line arguments u - **ID**: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md index 3b1b2a43c8..375e59c4b4 100644 --- a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md +++ b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments - **ID**: a87736a6-95cd-4728-8689-3c64d5026b3e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md index eb88b161df..e0f7bf6adb 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-l - **ID**: a23a0e20-0b1b-4a07-82e5-ec5f70811e7a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md index 8c1d968d90..a0c094e622 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 10d62950-0de5-4199-a710-cff9ea79b413 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md index 2953408c1d..678ee36da2 100644 --- a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md +++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments - **ID**: 3f6bbf22-093e-4cb4-9641-83f47b8444b6 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell.md b/docs/_posts/2021-08-25-getadgroup_with_powershell.md index af8324b559..5b1b5f0534 100644 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell.md +++ b/docs/_posts/2021-08-25-getadgroup_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 872e3063-0fc4-4e68-b2f3-f2b99184a708 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md index d6ae49ae13..59aa7b34bd 100644 --- a/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md +++ b/docs/_posts/2021-08-25-getadgroup_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: e4c73d68-794b-468d-b4d0-dac1772bbae7 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md index d37f90d3cf..0d41a77b0a 100644 --- a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md +++ b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 93c94be3-bead-4a60-860f-77ca3fe59903 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md index 56c9217909..a2eb17b049 100644 --- a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md +++ b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` with command-line util - **ID**: e02af35c-1de5-4afe-b4be-f45aba57272b -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md index 86f0716598..7a5ed0be7d 100644 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md +++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: df275a44-4527-443b-b884-7600e066e3eb -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md index 2bc811992a..013e8bb546 100644 --- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md +++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 67740bd3-1506-469c-b91d-effc322cc6e5 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md index 18e513ae6d..fb3722e66e 100644 --- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md +++ b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` executing the Get-ADDe - **ID**: 36e46ebe-065a-11ec-b4c7-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md index 8022b06cf0..4f7f87962e 100644 --- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 1ff7ccc8-065a-11ec-91e4-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md index 90705f40b5..69d7eb8ff7 100644 --- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md +++ b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` executing the Get ADUs - **ID**: 8b5ef342-065a-11ec-b0fc-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md index 9761feb7c0..a666433f2d 100644 --- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 737e1eb0-065a-11ec-921a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md index 673befa665..16180526f0 100644 --- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md +++ b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` executing the `Get-Dom - **ID**: b8f9947e-065a-11ec-aafb-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md index 345b7209ef..92d89c163e 100644 --- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: a360d2b2-065a-11ec-b0bf-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md index 987de0cddd..4fdd82071c 100644 --- a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md +++ b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md @@ -37,20 +37,13 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 09725404-a44f-4ed3-9efa-8ed5d69e4c53 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md index 9f60318d90..0f89e92f29 100644 --- a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md +++ b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command li - **ID**: 09336538-065a-11ec-8665-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md index 38f8a5c496..9a2f8a7870 100644 --- a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md +++ b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md @@ -38,20 +38,13 @@ This search looks for a process launching an `*.lnk` file under `C:\User*` or `* - **ID**: 5d814af1-1041-47b5-a9ac-d754e82e9a26 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.002](https://attack.mitre.org/techniques/T1566/002/) | Spearphishing Link | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md index 473e796538..418c81d91e 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md @@ -39,17 +39,12 @@ Review the source attempting to perform this activity against your environment. - **ID**: 29228ab4-0762-11ec-94aa-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1190](https://attack.mitre.org/techniques/T1190/) | Exploit Public-Facing Application | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index e94ae9722c..96aac471f1 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -42,20 +42,13 @@ Module - New-managementroleassignment can assign a management role to a manageme - **ID**: 2d10095e-05ae-11ec-8fdf-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md index 4e1d0662a5..62885a7688 100644 --- a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md +++ b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `nltest.exe` with command-line argument - **ID**: 41243735-89a7-4c83-bcdd-570aa78f00a1 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md index 60291b2db6..9521e0bacd 100644 --- a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md +++ b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li - **ID**: 9df16706-04a2-41e2-bbfe-9b38b34409d3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md index 4ef87f68cd..24c423f38e 100644 --- a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md +++ b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md @@ -38,17 +38,12 @@ During triage, review parallel security events to identify further suspicious ac - **ID**: 95b8061a-0a67-11ec-85ec-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1187](https://attack.mitre.org/techniques/T1187/) | Forced Authentication | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md index bf1eff8a6d..23116162ca 100644 --- a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md +++ b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md @@ -35,17 +35,12 @@ The following analytic identifes Event Code 4768, A `Kerberos authentication tic - **ID**: e3ef244e-0a67-11ec-abf2-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md index 8d166c8a3c..9ea5c4a0f1 100644 --- a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md +++ b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen - **ID**: 9fb562f4-42f8-4139-8e11-a82edf7ed718 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md index 0c4f631a29..b9f5b1bceb 100644 --- a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md +++ b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md @@ -34,17 +34,12 @@ This search looks for disable security step in CircleCI pipeline. - **ID**: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md index dfaffe5267..f3438f166d 100644 --- a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md +++ b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments - **ID**: 64c7adaa-48ee-483c-b0d6-7175bc65e6cc -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md index fd95fc6938..9995877c84 100644 --- a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md +++ b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `dsquery.exe` with command-line argumen - **ID**: f0c9d62f-a232-4edd-b17e-bc409fb133d4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.002](https://attack.mitre.org/techniques/T1069/002/) | Domain Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md index b0f0683b18..0fee3dfc59 100644 --- a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md +++ b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: a9a1da02-8e27-4bf7-a348-f4389c9da487 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md index 9ad7d62b13..1571d739e1 100644 --- a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md +++ b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 29b99201-723c-4118-847a-db2b3d3fb8ea -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md index a2bdc354e9..34aadd6bbd 100644 --- a/docs/_posts/2021-09-01-github_commit_in_develop.md +++ b/docs/_posts/2021-09-01-github_commit_in_develop.md @@ -34,17 +34,12 @@ This search is to detect a pushed or commit to develop branch. This is to avoid - **ID**: f3030cb6-0b02-11ec-8f22-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1199](https://attack.mitre.org/techniques/T1199/) | Trusted Relationship | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md index 1470737198..2e0beed829 100644 --- a/docs/_posts/2021-09-01-github_dependabot_alert.md +++ b/docs/_posts/2021-09-01-github_dependabot_alert.md @@ -37,20 +37,13 @@ This search looks for Dependabot Alerts in Github logs. - **ID**: 05032b04-4469-4034-9df7-05f607d75cba -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access | - - - | [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md index ab3824347a..ec7b5205bd 100644 --- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md +++ b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md @@ -37,20 +37,13 @@ This search looks for Pull Request from unknown user. - **ID**: 9d7b9100-8878-4404-914e-ca5e551a641e -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1195.001](https://attack.mitre.org/techniques/T1195/001/) | Compromise Software Dependencies and Development Tools | Initial Access | - - - | [T1195](https://attack.mitre.org/techniques/T1195/) | Supply Chain Compromise | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md index 9a0748ddeb..bb6b66707f 100644 --- a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md +++ b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_at_the_destination_device.md @@ -36,20 +36,13 @@ This detection identifies potential Pass the Token or Pass the Hash credential e - **ID**: 82e76b80-5cdb-4899-9b43-85dbe777b36d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - - | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md index cf43b3e9da..0e11f8e291 100644 --- a/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md +++ b/docs/_posts/2021-09-01-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md @@ -36,20 +36,13 @@ This detection identifies potential Pass the Token or Pass the Hash credential e - **ID**: 1058ba3e-a698-49bc-a1e5-7cedece4ea87 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1550](https://attack.mitre.org/techniques/T1550/) | Use Alternate Authentication Material | Defense Evasion, Lateral Movement | - - | [T1550.002](https://attack.mitre.org/techniques/T1550/002/) | Pass the Hash | Defense Evasion, Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md index 3afcd62983..b0c3aa48ce 100644 --- a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md +++ b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 70803451-0047-4e12-9d63-77fa7eb8649c -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md index f6044202b2..123962a7e3 100644 --- a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md +++ b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments - **ID**: d82eced3-b1dc-42ab-859e-a2fc98827359 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md index aedf125379..d91f8bdbb7 100644 --- a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md +++ b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md @@ -34,17 +34,12 @@ This search looks for disable security job in CircleCI pipeline. - **ID**: 4a2fdd41-c578-4cd4-9ef7-980e352517f2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md index 57dcb0d70b..0a0815e1fd 100644 --- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md +++ b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md @@ -34,17 +34,12 @@ This analytic identifies Get-ForestTrust from PowerSploit in order to gather dom - **ID**: 584f4884-0bf1-11ec-a5ec-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md index a1d8f0f075..99379a9c70 100644 --- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md +++ b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md @@ -36,17 +36,12 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 70fac80e-0bf1-11ec-9ba0-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md index 1e184c509c..92b5e1db54 100644 --- a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md +++ b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: f64da023-b988-4775-8d57-38e512beb56e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md index be49479a4a..9de9041581 100644 --- a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md +++ b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 676b600a-a94d-4951-b346-11329431e6c1 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md b/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md index 3da5c177e4..23a69c4cd9 100644 --- a/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md +++ b/docs/_posts/2021-09-06-add_defaultuser_and_password_in_registry.md @@ -37,20 +37,13 @@ this search is to detect a suspicious registry modification to implement auto ad - **ID**: d4a3eb62-0f1e-11ec-a971-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access | - - - | [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md b/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md index af62c19629..1a1a1f1bac 100644 --- a/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md +++ b/docs/_posts/2021-09-06-auto_admin_logon_registry_entry.md @@ -37,20 +37,13 @@ this search is to detect a suspicious registry modification to implement auto ad - **ID**: 1379d2b8-0f18-11ec-8ca3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1552.002](https://attack.mitre.org/techniques/T1552/002/) | Credentials in Registry | Credential Access | - - - | [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md index 3ea46e0234..4b4c0d958d 100644 --- a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md +++ b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md @@ -34,17 +34,12 @@ This search is to detect a suspicious bcdedit commandline to configure the host - **ID**: dc7a8004-0f18-11ec-8c54-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md index 9736c68482..f306569dc2 100644 --- a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md +++ b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md @@ -34,17 +34,12 @@ This search is to detect a suspicious bcdedit commandline to configure the host - **ID**: 81f1dce0-0f18-11ec-a5d7-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md index fd538cbd32..ab0c3436be 100644 --- a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md +++ b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md @@ -37,20 +37,13 @@ This search correlations detections by repository and risk_score - **ID**: 8da9fdd9-6a1b-4ae0-8a34-8c25e6be9687 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md index 1a6faee558..8d5a12789d 100644 --- a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md +++ b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md @@ -37,20 +37,13 @@ This search correlations detections by user and risk_score - **ID**: 610e12dc-b6fa-4541-825e-4a0b3b6f6773 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204.003](https://attack.mitre.org/techniques/T1204/003/) | Malicious Image | Execution | - - - | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md index 2199e6d059..659398eedd 100644 --- a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md +++ b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: c5a31f80-5888-4d81-9f78-1cc65026316e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md index 32eefd3a36..262d91b0bc 100644 --- a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md +++ b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: ed550c19-712e-43f6-bd19-6f58f61b3a5e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md index afd6d91110..1b8a164f9f 100644 --- a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md +++ b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 868ee0e4-52ab-484a-833a-6d85b7c028d0 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md index 4c044be89d..6b985257ba 100644 --- a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md +++ b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 7141122c-3bc2-4aaa-ab3b-7a85a0bbefc3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md b/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md index c552f86aba..7c74d5e189 100644 --- a/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md +++ b/docs/_posts/2021-09-07-registry_keys_used_for_persistence.md @@ -39,20 +39,13 @@ The search looks for modifications to registry keys that can be used to launch a - **ID**: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.001](https://attack.mitre.org/techniques/T1547/001/) | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md index 40a6364cf5..81d9a2ad96 100644 --- a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md +++ b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md @@ -37,20 +37,13 @@ This analytic is to detect an application try to connect and create ADSI Object - **ID**: 991eb510-0fc6-11ec-82d3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-07-system_information_discovery_detection.md b/docs/_posts/2021-09-07-system_information_discovery_detection.md index 4e59dbb88c..8c7d24c67f 100644 --- a/docs/_posts/2021-09-07-system_information_discovery_detection.md +++ b/docs/_posts/2021-09-07-system_information_discovery_detection.md @@ -34,17 +34,12 @@ Detect system information discovery techniques used by attackers to understand c - **ID**: 8e99f89e-ae58-4ebc-bf52-ae0b1a277e72 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1082](https://attack.mitre.org/techniques/T1082/) | System Information Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md index 8fdd2191bc..d83e894d7d 100644 --- a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md +++ b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md @@ -38,20 +38,13 @@ The following detection identifies control.exe loading either a .cpl or .inf fro - **ID**: 10423ac4-10c9-11ec-8dc4-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.002](https://attack.mitre.org/techniques/T1218/002/) | Control Panel | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md index ab7403bf2f..56cd1c4566 100644 --- a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md +++ b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md @@ -37,20 +37,13 @@ This search looks for the creation of local administrator accounts using net.exe - **ID**: b89919ed-fe5f-492c-b139-151bb162040e -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1136.001](https://attack.mitre.org/techniques/T1136/001/) | Local Account | Persistence | - - - | [T1136](https://attack.mitre.org/techniques/T1136/) | Create Account | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-08-office_spawning_control.md b/docs/_posts/2021-09-08-office_spawning_control.md index 92d613e8ef..11005c526f 100644 --- a/docs/_posts/2021-09-08-office_spawning_control.md +++ b/docs/_posts/2021-09-08-office_spawning_control.md @@ -38,20 +38,13 @@ The following detection identifies control.exe spawning from an office product. - **ID**: 053e027c-10c7-11ec-8437-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md index 61b8e8f940..c47e1edcc9 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md @@ -38,20 +38,13 @@ The following hunting detection identifies rundll32.exe with `control_rundll` wi - **ID**: c8e7ced0-10c5-11ec-8b03-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md index e3cb4cd259..4b38ffe88a 100644 --- a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md +++ b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md @@ -38,20 +38,13 @@ The following detection identifies rundll32.exe with `control_rundll` within the - **ID**: 1adffe86-10c3-11ec-8ce6-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-09-extraction_of_registry_hives.md b/docs/_posts/2021-09-09-extraction_of_registry_hives.md index 91224ac63c..203cc92a7b 100644 --- a/docs/_posts/2021-09-09-extraction_of_registry_hives.md +++ b/docs/_posts/2021-09-09-extraction_of_registry_hives.md @@ -37,20 +37,13 @@ The following analytic identifies the use of `reg.exe` exporting Windows Registr - **ID**: 8bbb7d58-b360-11eb-ba21-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md index 810c35380d..bd17c88825 100644 --- a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md +++ b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md @@ -38,20 +38,13 @@ The following detection identifies the module load of mshtml.dll into an Office - **ID**: 5f1c168e-118b-11ec-84ff-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md index 51d8fd153c..ccd3386415 100644 --- a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md +++ b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 091712ff-b02a-4d43-82ed-34765515d95d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md index 7b71908a5f..ad9faf77fb 100644 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md +++ b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `arp.exe` utilized to get a listing of - **ID**: ae008c0f-83bd-4ed4-9350-98d4328e15d2 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md index dcbe64c781..07fd8a7b22 100644 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md +++ b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `net.exe` with command-line arguments u - **ID**: 640337e5-6e41-4b7f-af06-9d9eab5e1e2d -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md index 75debd4392..532f633a42 100644 --- a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md +++ b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `netstat.exe` with command-line argumen - **ID**: 2cf5cc25-f39a-436d-a790-4857e5995ede -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1049](https://attack.mitre.org/techniques/T1049/) | System Network Connections Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md index c71a084ac6..25125b805f 100644 --- a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md +++ b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md @@ -38,20 +38,13 @@ The following analytic identifies behavior related to CVE-2021-40444. Whereas th - **ID**: f48cd1d4-125a-11ec-a447-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md index 2e5240e7ff..c10601a0eb 100644 --- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md +++ b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powerhsell.exe` with command-line argu - **ID**: 7eb9c3d5-c98c-4088-acc5-8240bad15379 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md index c25bd5cf0b..c409e1d699 100644 --- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md +++ b/docs/_posts/2021-09-13-getcurrent_user_with_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 80879283-c30f-44f7-8471-d1381f6d437a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md index 0ec8369b39..d6c37080b1 100644 --- a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md +++ b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md @@ -37,20 +37,13 @@ This search is to detect a execution of jscript using cscript process. Commonly - **ID**: 002f1e24-146e-11ec-a470-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md index b30ddad447..39498c691e 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md @@ -37,20 +37,13 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o - **ID**: 0b0c40dc-14a6-11ec-b267-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md index 3c77c33b18..64568a6b8f 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md @@ -37,20 +37,13 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o - **ID**: 2eba3d36-14a6-11ec-a682-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-office_application_drop_executable.md b/docs/_posts/2021-09-13-office_application_drop_executable.md index 7ed9136387..dbc5c15020 100644 --- a/docs/_posts/2021-09-13-office_application_drop_executable.md +++ b/docs/_posts/2021-09-13-office_application_drop_executable.md @@ -37,20 +37,13 @@ This search is to detect a suspicious MS office application that drop or create - **ID**: 73ce70c4-146d-11ec-9184-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_query.md b/docs/_posts/2021-09-13-system_user_discovery_with_query.md index 20322c2d36..0bdff3fcbe 100644 --- a/docs/_posts/2021-09-13-system_user_discovery_with_query.md +++ b/docs/_posts/2021-09-13-system_user_discovery_with_query.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `query.exe` with command-line arguments - **ID**: ad03bfcf-8a91-4bc2-a500-112993deba87 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md index 262b1aa245..17f9d0f072 100644 --- a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md +++ b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `whoami.exe` without any arguments. Thi - **ID**: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md index cd0d0390dc..1f967c3102 100644 --- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md +++ b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md @@ -34,17 +34,12 @@ This analytic looks for the execution of `powershell.exe` with command-line argu - **ID**: 0cdf318b-a0dd-47d7-b257-c621c0247de8 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md index b0303f4595..879e3f5e63 100644 --- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md +++ b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell_script_block.md @@ -34,17 +34,12 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - **ID**: 77f41d9e-b8be-47e3-ab35-5776f5ec1d20 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md index 830b54060f..6afff6cc48 100644 --- a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md +++ b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md @@ -34,17 +34,12 @@ This search is to detect a suspicious wmic.exe process or renamed wmic process t - **ID**: 004e32e2-146d-11ec-a83f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1220](https://attack.mitre.org/techniques/T1220/) | XSL Script Processing | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md index 6be2120915..23d9ea2db7 100644 --- a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md +++ b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md @@ -37,20 +37,13 @@ This search is to detect a suspicious parent process execution of commandline to - **ID**: 6c3f7dd8-153c-11ec-ac2d-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1059.007](https://attack.mitre.org/techniques/T1059/007/) | JavaScript | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md index 6a230c4883..7ad8f6ea27 100644 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md +++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md @@ -37,20 +37,13 @@ The following hunting analytic identifies the use of `Get-WMIObject Win32_Group` - **ID**: 5434f670-155d-11ec-8cca-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md index 3e0d098b1c..feecd95330 100644 --- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md +++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery_with_script_block_logging.md @@ -38,20 +38,13 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: 69df7f7c-155d-11ec-a055-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-net_localgroup_discovery.md b/docs/_posts/2021-09-14-net_localgroup_discovery.md index cf3f88a16a..84ec97fb39 100644 --- a/docs/_posts/2021-09-14-net_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-net_localgroup_discovery.md @@ -37,20 +37,13 @@ The following hunting analytic will identify the use of localgroup discovery usi - **ID**: 54f5201e-155b-11ec-a6e2-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md index 7451952c47..a43de98afb 100644 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md @@ -37,20 +37,13 @@ The following hunting analytic identifies the use of `get-localgroup` being used - **ID**: b71adfcc-155b-11ec-9413-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md index 4db9a15d7d..fbaeb39392 100644 --- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md +++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md @@ -39,20 +39,13 @@ During triage, review parallel processes using an EDR product or 4688 events. It - **ID**: d7c6ad22-155c-11ec-bb64-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-14-wmic_group_discovery.md b/docs/_posts/2021-09-14-wmic_group_discovery.md index 2f89a8c806..4b790367fa 100644 --- a/docs/_posts/2021-09-14-wmic_group_discovery.md +++ b/docs/_posts/2021-09-14-wmic_group_discovery.md @@ -39,20 +39,13 @@ During triage, review parallel processes and identify any further suspicious beh - **ID**: 83317b08-155b-11ec-8e00-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1069](https://attack.mitre.org/techniques/T1069/) | Permission Groups Discovery | Discovery | - - | [T1069.001](https://attack.mitre.org/techniques/T1069/001/) | Local Groups | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md index 5f9a2a4339..640558ab41 100644 --- a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md +++ b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md @@ -34,17 +34,12 @@ This search is to detect a suspicious whoami execution to check if the cmd or sh - **ID**: a9079b18-1633-11ec-859c-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1033](https://attack.mitre.org/techniques/T1033/) | System Owner/User Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md index 773d4c0fdb..ccaf83d5a2 100644 --- a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md +++ b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md @@ -37,20 +37,13 @@ This search is to detect an anomaly event of non-chrome process accessing the fi - **ID**: 81263de4-160a-11ec-944f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - - | [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md index e3b816a7ca..3dd644851c 100644 --- a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md +++ b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md @@ -37,20 +37,13 @@ This search is to detect an anomaly event of non-firefox process accessing the f - **ID**: e6fc13b0-1609-11ec-b533-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - - | [T1555.003](https://attack.mitre.org/techniques/T1555/003/) | Credentials from Web Browsers | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-account_discovery_with_net_app.md b/docs/_posts/2021-09-16-account_discovery_with_net_app.md index dce7514850..94b7e04ffe 100644 --- a/docs/_posts/2021-09-16-account_discovery_with_net_app.md +++ b/docs/_posts/2021-09-16-account_discovery_with_net_app.md @@ -37,20 +37,13 @@ this search is to detect a potential account discovery series of command used by - **ID**: 339805ce-ac30-11eb-b87d-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087.002](https://attack.mitre.org/techniques/T1087/002/) | Domain Account | Discovery | - - - | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md index fd45a5ecab..4349f3cee7 100644 --- a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md +++ b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md @@ -38,20 +38,13 @@ Attempt To Add Certificate To Untrusted Store - **ID**: 6bc5243e-ef36-45dc-9b12-f4a6be131159 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1553.004](https://attack.mitre.org/techniques/T1553/004/) | Install Root Certificate | Defense Evasion | - - - | [T1553](https://attack.mitre.org/techniques/T1553/) | Subvert Trust Controls | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md index f470bb422b..1b23709a92 100644 --- a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md @@ -37,20 +37,13 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th - **ID**: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-batch_file_write_to_system32.md b/docs/_posts/2021-09-16-batch_file_write_to_system32.md index fdabb3b3bf..80322c1ade 100644 --- a/docs/_posts/2021-09-16-batch_file_write_to_system32.md +++ b/docs/_posts/2021-09-16-batch_file_write_to_system32.md @@ -37,20 +37,13 @@ The search looks for a batch file (.bat) written to the Windows system directory - **ID**: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1204](https://attack.mitre.org/techniques/T1204/) | User Execution | Execution | - - | [T1204.002](https://attack.mitre.org/techniques/T1204/002/) | Malicious File | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-bits_job_persistence.md b/docs/_posts/2021-09-16-bits_job_persistence.md index 43b9031329..47cfbd9c72 100644 --- a/docs/_posts/2021-09-16-bits_job_persistence.md +++ b/docs/_posts/2021-09-16-bits_job_persistence.md @@ -35,17 +35,12 @@ The following query identifies Microsoft Background Intelligent Transfer Service - **ID**: e97a5ffe-90bf-11eb-928a-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-bitsadmin_download_file.md b/docs/_posts/2021-09-16-bitsadmin_download_file.md index 3a65ff0ce7..422a40f9cb 100644 --- a/docs/_posts/2021-09-16-bitsadmin_download_file.md +++ b/docs/_posts/2021-09-16-bitsadmin_download_file.md @@ -38,21 +38,13 @@ The following query identifies Microsoft Background Intelligent Transfer Service - **ID**: 80630ff4-8e4c-11eb-aab5-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1197](https://attack.mitre.org/techniques/T1197/) | BITS Jobs | Defense Evasion, Persistence | - - - | [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md index c15f94872a..e60b1d78b0 100644 --- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md +++ b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md @@ -37,20 +37,13 @@ This search detects the use of wmic and Powershell to create a shadow copy. - **ID**: 2ed8b538-d284-449a-be1d-82ad1dbd186b -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md index c37089737e..80680eb308 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md @@ -37,20 +37,13 @@ This search detects credential dumping using copy command from a shadow copy. - **ID**: d8c406fe-23d2-45f3-a983-1abe7b83ff3b -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md index 79c3a4d4b7..4448fb737f 100644 --- a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md +++ b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md @@ -37,20 +37,13 @@ This search detects the creation of a symlink to a shadow copy. - **ID**: c5eac648-fae0-4263-91a6-773df1f4c903 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.003](https://attack.mitre.org/techniques/T1003/003/) | NTDS | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_html_help_renamed.md b/docs/_posts/2021-09-16-detect_html_help_renamed.md index 358a4d1412..9458afb7fa 100644 --- a/docs/_posts/2021-09-16-detect_html_help_renamed.md +++ b/docs/_posts/2021-09-16-detect_html_help_renamed.md @@ -37,20 +37,13 @@ The following analytic identifies a renamed instance of hh.exe (HTML Help) execu - **ID**: 62fed254-513b-460e-953d-79771493a9f3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md index 68e096266a..d4440e8afc 100644 --- a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md @@ -37,20 +37,13 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM - **ID**: 8c5835b9-39d9-438b-817c-95f14c69a31e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md index 837abc9e6a..17f24491f2 100644 --- a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md +++ b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md @@ -37,20 +37,13 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM - **ID**: 0b2eefa5-5508-450d-b970-3dd2fb761aec -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.001](https://attack.mitre.org/techniques/T1218/001/) | Compiled HTML File | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md index da10509dcc..d108738738 100644 --- a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md +++ b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md @@ -37,20 +37,13 @@ The following analytic identifies "mshta.exe" execution with inline prot - **ID**: a0873b32-5b68-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_mshta_renamed.md b/docs/_posts/2021-09-16-detect_mshta_renamed.md index 2f9b9ab1df..7d760e0a46 100644 --- a/docs/_posts/2021-09-16-detect_mshta_renamed.md +++ b/docs/_posts/2021-09-16-detect_mshta_renamed.md @@ -37,20 +37,13 @@ The following analytic identifies renamed instances of mshta.exe executing. Msht - **ID**: 8f45fcf0-5b68-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md index 88bcadcfb3..b44ceb8b00 100644 --- a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md +++ b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md @@ -37,20 +37,13 @@ This analytic identifies when Microsoft HTML Application Host (mshta.exe) utilit - **ID**: 9b3af1e6-5b68-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.005](https://attack.mitre.org/techniques/T1218/005/) | Mshta | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md index ca9f94659d..5cd8f81d13 100644 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md @@ -37,20 +37,13 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla - **ID**: b89919ed-fe5f-492c-b139-151xb162040e -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - - | [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_renamed_7-zip.md b/docs/_posts/2021-09-16-detect_renamed_7-zip.md index 0c9ec8c7bc..89483337d8 100644 --- a/docs/_posts/2021-09-16-detect_renamed_7-zip.md +++ b/docs/_posts/2021-09-16-detect_renamed_7-zip.md @@ -37,20 +37,13 @@ The following analytic identifies renamed 7-Zip usage using Sysmon. At this stag - **ID**: 4057291a-b8cf-11eb-95fe-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - - - | [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_renamed_psexec.md b/docs/_posts/2021-09-16-detect_renamed_psexec.md index 1f3614ac69..ee7899af8b 100644 --- a/docs/_posts/2021-09-16-detect_renamed_psexec.md +++ b/docs/_posts/2021-09-16-detect_renamed_psexec.md @@ -39,20 +39,13 @@ The following analytic identifies renamed instances of `PsExec.exe` being utiliz - **ID**: 683e6196-b8e8-11eb-9a79-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - - | [T1569.002](https://attack.mitre.org/techniques/T1569/002/) | Service Execution | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_renamed_rclone.md b/docs/_posts/2021-09-16-detect_renamed_rclone.md index c820aedd4e..b6649116c9 100644 --- a/docs/_posts/2021-09-16-detect_renamed_rclone.md +++ b/docs/_posts/2021-09-16-detect_renamed_rclone.md @@ -33,17 +33,12 @@ The following analytic identifies the usage of `rclone.exe`, renamed, being used - **ID**: 6dca1124-b3ec-11eb-9328-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-detect_renamed_winrar.md b/docs/_posts/2021-09-16-detect_renamed_winrar.md index 912ea467df..ce07284365 100644 --- a/docs/_posts/2021-09-16-detect_renamed_winrar.md +++ b/docs/_posts/2021-09-16-detect_renamed_winrar.md @@ -38,20 +38,13 @@ The following analtyic identifies renamed instances of `WinRAR.exe`. In most cas - **ID**: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1560.001](https://attack.mitre.org/techniques/T1560/001/) | Archive via Utility | Collection | - - - | [T1560](https://attack.mitre.org/techniques/T1560/) | Archive Collected Data | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md index 5f79a4fa07..ea45e5094a 100644 --- a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md +++ b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md @@ -38,20 +38,13 @@ During triage, confirm this is procdump.exe executing. If it is the first time a - **ID**: 3742ebfe-64c2-11eb-ae93-0242ac130002 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1003.001](https://attack.mitre.org/techniques/T1003/001/) | LSASS Memory | Credential Access | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_net.md b/docs/_posts/2021-09-16-local_account_discovery_with_net.md index 958506e34f..4db5c62b08 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_net.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_net.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li - **ID**: 5d0d4830-0133-11ec-bae3-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md index 44553e708a..3812e87b7d 100644 --- a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md +++ b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md @@ -37,20 +37,13 @@ This analytic looks for the execution of `wmic.exe` with command-line arguments - **ID**: 4902d7aa-0134-11ec-9d65-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - - | [T1087.001](https://attack.mitre.org/techniques/T1087/001/) | Local Account | Discovery | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-office_product_spawning_wmic.md b/docs/_posts/2021-09-16-office_product_spawning_wmic.md index e6af46b2c2..0dca47d37c 100644 --- a/docs/_posts/2021-09-16-office_product_spawning_wmic.md +++ b/docs/_posts/2021-09-16-office_product_spawning_wmic.md @@ -37,20 +37,13 @@ The following detection identifies the latest behavior utilized by Ursnif malwar - **ID**: ffc236d6-a6c9-11eb-95f1-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-16-processes_launching_netsh.md b/docs/_posts/2021-09-16-processes_launching_netsh.md index 8cf4892535..0b2b98b3a7 100644 --- a/docs/_posts/2021-09-16-processes_launching_netsh.md +++ b/docs/_posts/2021-09-16-processes_launching_netsh.md @@ -37,20 +37,13 @@ This search looks for processes launching netsh.exe. Netsh is a command-line scr - **ID**: b89919ed-fe5f-492c-b139-95dbb162040e -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.004](https://attack.mitre.org/techniques/T1562/004/) | Disable or Modify System Firewall | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md index 02f94fc0b8..f96b6733f5 100644 --- a/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-detect_regasm_with_no_command_line_arguments.md @@ -37,20 +37,13 @@ The following analytic identifies regasm.exe with no command line arguments. Thi - **ID**: c3bc1430-04e7-4178-835f-047d8e6e97df -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md index 434af6a26f..f604fc4f3e 100644 --- a/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-detect_regsvcs_with_no_command_line_arguments.md @@ -37,20 +37,13 @@ The following analytic identifies regsvcs.exe with no command line arguments. Th - **ID**: 6b74d578-a02e-4e94-a0d1-39440d0bf254 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.009](https://attack.mitre.org/techniques/T1218/009/) | Regsvcs/Regasm | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md index 14fc445057..934d5fdf05 100644 --- a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md +++ b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md @@ -37,20 +37,13 @@ This search is to detect potential malicious office document executing lolbin ch - **ID**: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1566](https://attack.mitre.org/techniques/T1566/) | Phishing | Initial Access | - - | [T1566.001](https://attack.mitre.org/techniques/T1566/001/) | Spearphishing Attachment | Initial Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md index 9e1cfc6870..1876e3ee64 100644 --- a/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_dllhost_no_command_line_arguments.md @@ -35,17 +35,12 @@ The following analytic identifies DLLHost.exe with no command line arguments. It - **ID**: ff61e98c-0337-4593-a78f-72a676c56f26 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md index a6f04ffddf..2f7f982825 100644 --- a/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_gpupdate_no_command_line_arguments.md @@ -35,17 +35,12 @@ The following analytic identifies gpupdate.exe with no command line arguments. I - **ID**: f308490a-473a-40ef-ae64-dd7a6eba284a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md index ee62c0c27d..2bd20a21aa 100644 --- a/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md +++ b/docs/_posts/2021-09-20-suspicious_microsoft_workflow_compiler_rename.md @@ -40,24 +40,14 @@ The following analytic identifies a renamed instance of microsoft.workflow.compi - **ID**: f0db4464-55d9-11eb-ae93-0242ac130002 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md index df83627a5a..450254f040 100644 --- a/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_rundll32_no_command_line_arguments.md @@ -38,20 +38,13 @@ The following analytic identifies rundll32.exe with no command line arguments. I - **ID**: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md b/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md index 682cb4ac09..79f29a8138 100644 --- a/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md +++ b/docs/_posts/2021-09-20-suspicious_searchprotocolhost_no_command_line_arguments.md @@ -35,17 +35,12 @@ The following analytic identifies searchprotocolhost.exe with no command line ar - **ID**: f52d2db8-31f9-4aa7-a176-25779effe55c -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md index 803756d04b..8f689d0b4c 100644 --- a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md +++ b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md @@ -34,17 +34,12 @@ This search is to detect file creation in remcos folder in appdata which is the - **ID**: 25ae862a-1ac3-11ec-94a1-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md index ff954f11e8..f6f15a9bda 100644 --- a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md +++ b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md @@ -34,17 +34,12 @@ This search is to detect a suspicious creation of image in appdata folder made b - **ID**: f6f904c4-1ac0-11ec-806b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md index a5d12022e3..75b08accc6 100644 --- a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md +++ b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md @@ -34,17 +34,12 @@ This analytic is to detect a suspicious creation of .wav file in appdata folder. - **ID**: 5be109e6-1ac5-11ec-b421-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-24-remcos_client_registry_install_entry.md b/docs/_posts/2021-09-24-remcos_client_registry_install_entry.md index 64556537bd..7e175b3bad 100644 --- a/docs/_posts/2021-09-24-remcos_client_registry_install_entry.md +++ b/docs/_posts/2021-09-24-remcos_client_registry_install_entry.md @@ -34,17 +34,12 @@ This search detects registry key license at host where Remcos RAT agent is insta - **ID**: f2a1615a-1d63-11ec-97d2-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-27-change_default_file_association.md b/docs/_posts/2021-09-27-change_default_file_association.md index 5a490f5668..e51853e2b0 100644 --- a/docs/_posts/2021-09-27-change_default_file_association.md +++ b/docs/_posts/2021-09-27-change_default_file_association.md @@ -39,20 +39,13 @@ This analytic is developed to detect suspicious registry modification to change - **ID**: 462d17d8-1f71-11ec-ad07-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546.001](https://attack.mitre.org/techniques/T1546/001/) | Change Default File Association | Privilege Escalation, Persistence | - - - | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md index 3b72af1567..d1b88e9ca1 100644 --- a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md +++ b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md @@ -39,20 +39,13 @@ This search is to detect a suspicious modification of registry entry to persist - **ID**: 4c38c264-1f74-11ec-b5fa-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1037](https://attack.mitre.org/techniques/T1037/) | Boot or Logon Initialization Scripts | Persistence, Privilege Escalation | - - | [T1037.001](https://attack.mitre.org/techniques/T1037/001/) | Logon Script (Windows) | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md index 756516b423..9974ca8484 100644 --- a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md +++ b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md @@ -39,20 +39,13 @@ This analytic is developed to detect possible event trigger execution through sc - **ID**: 58cea3ec-1f6d-11ec-8560-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1546](https://attack.mitre.org/techniques/T1546/) | Event Triggered Execution | Privilege Escalation, Persistence | - - | [T1546.002](https://attack.mitre.org/techniques/T1546/002/) | Screensaver | Privilege Escalation, Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-28-active_setup_registry_autostart.md b/docs/_posts/2021-09-28-active_setup_registry_autostart.md index 0e8e12d2f9..31149547f2 100644 --- a/docs/_posts/2021-09-28-active_setup_registry_autostart.md +++ b/docs/_posts/2021-09-28-active_setup_registry_autostart.md @@ -39,20 +39,13 @@ This analytic is to detect a suspicious modification of the active setup registr - **ID**: f64579c0-203f-11ec-abcc-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.014](https://attack.mitre.org/techniques/T1547/014/) | Active Setup | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md index 9ca5d11f25..62ecec293c 100644 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -41,20 +41,13 @@ This analytic is to detect a suspicious modification or new registry entry regar - **ID**: 1f5b68aa-2037-11ec-898e-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.012](https://attack.mitre.org/techniques/T1547/012/) | Print Processors | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-29-disable_uac_remote_restriction.md b/docs/_posts/2021-09-29-disable_uac_remote_restriction.md index 97f726217b..b7eb968878 100644 --- a/docs/_posts/2021-09-29-disable_uac_remote_restriction.md +++ b/docs/_posts/2021-09-29-disable_uac_remote_restriction.md @@ -39,20 +39,13 @@ This analytic is to detect a suspicious modification of registry to disable UAC - **ID**: 9928b732-210e-11ec-b65e-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1548.002](https://attack.mitre.org/techniques/T1548/002/) | Bypass User Account Control | Privilege Escalation, Defense Evasion | - - - | [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-29-time_provider_persistence_registry.md b/docs/_posts/2021-09-29-time_provider_persistence_registry.md index 6a60191f81..6ccd462c83 100644 --- a/docs/_posts/2021-09-29-time_provider_persistence_registry.md +++ b/docs/_posts/2021-09-29-time_provider_persistence_registry.md @@ -39,20 +39,13 @@ This analytic is to detect a suspiciouos modification of time provider registry - **ID**: 5ba382c4-2105-11ec-8d8f-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1547.003](https://attack.mitre.org/techniques/T1547/003/) | Time Providers | Persistence, Privilege Escalation | - - - | [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-09-29-verclsid_clsid_execution.md b/docs/_posts/2021-09-29-verclsid_clsid_execution.md index 1943b5ce2e..de9f14450a 100644 --- a/docs/_posts/2021-09-29-verclsid_clsid_execution.md +++ b/docs/_posts/2021-09-29-verclsid_clsid_execution.md @@ -37,20 +37,13 @@ This analytic is to detect a possible abuse of verclsid to execute malicious fil - **ID**: 61e9a56a-20fa-11ec-8ba3-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218.012](https://attack.mitre.org/techniques/T1218/012/) | Verclsid | Defense Evasion | - - - | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md index 5e0c8ddf49..f424dac917 100644 --- a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md +++ b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md @@ -37,20 +37,13 @@ This analytic is to detect a suspicious wscript commandline to execute vbscript. - **ID**: 35159940-228f-11ec-8a49-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059.005](https://attack.mitre.org/techniques/T1059/005/) | Visual Basic | Execution | - - - | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md index 754a545712..342c1ab714 100644 --- a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md +++ b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md @@ -37,20 +37,13 @@ This analytic is to detect a suspicious child process of MSBuild spawned by Wind - **ID**: 213b3148-24ea-11ec-93a2-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1127.001](https://attack.mitre.org/techniques/T1127/001/) | MSBuild | Defense Evasion | - - - | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md b/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md index a104b351ed..e9c59e0ece 100644 --- a/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md +++ b/docs/_posts/2021-10-04-regsvr32_silent_param_dll_loading.md @@ -37,20 +37,13 @@ This analytic is to detect a loading of dll using regsvr32 application with sile - **ID**: f421c250-24e7-11ec-bc43-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-detect_exchange_web_shell.md b/docs/_posts/2021-10-05-detect_exchange_web_shell.md index 7b2f8551be..1d3bbf977a 100644 --- a/docs/_posts/2021-10-05-detect_exchange_web_shell.md +++ b/docs/_posts/2021-10-05-detect_exchange_web_shell.md @@ -37,20 +37,13 @@ The following query identifies suspicious .aspx created in 3 paths identified by - **ID**: 8c14eeee-2af1-4a4b-bda8-228da0f4862a -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1505](https://attack.mitre.org/techniques/T1505/) | Server Software Component | Persistence | - - | [T1505.003](https://attack.mitre.org/techniques/T1505/003/) | Web Shell | Persistence | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md b/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md index a9d371a1c1..93c548c2d4 100644 --- a/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md +++ b/docs/_posts/2021-10-05-disable_security_logs_using_minint_registry.md @@ -34,17 +34,12 @@ This analytic is to detect a suspicious registry modification to disable securit - **ID**: 39ebdc68-25b9-11ec-aec7-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md b/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md index 10c1c2c597..42fe139b6f 100644 --- a/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md +++ b/docs/_posts/2021-10-05-enable_wdigest_uselogoncredential_registry.md @@ -37,21 +37,13 @@ This analytic is to detect a suspicious registry modification to enable plain te - **ID**: 0c7d8ffe-25b1-11ec-9f39-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md index bc190505e2..5a6c6c1ee3 100644 --- a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md +++ b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md @@ -37,20 +37,13 @@ The following analytic identifies a process modifying the registry with a known - **ID**: 127c8d08-25ff-11ec-9223-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218.010](https://attack.mitre.org/techniques/T1218/010/) | Regsvr32 | Defense Evasion | - - - | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md index 74f082faaf..3523005eec 100644 --- a/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md +++ b/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md @@ -38,20 +38,13 @@ The following hunting analytic identifies PowerShell commands utilizing the Wind - **ID**: ee18ed37-0802-4268-9435-b3b91aaa18db -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | - - - | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-malicious_powershell_process_-_encoded_command.md b/docs/_posts/2021-10-05-malicious_powershell_process_-_encoded_command.md index 6257a189a9..c19ddd922a 100644 --- a/docs/_posts/2021-10-05-malicious_powershell_process_-_encoded_command.md +++ b/docs/_posts/2021-10-05-malicious_powershell_process_-_encoded_command.md @@ -38,17 +38,12 @@ Alternatively, may use regex per matching here https://regexr.com/662ov. - **ID**: c4db14d9-7909-48b4-a054-aa14d89dbb19 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1027](https://attack.mitre.org/techniques/T1027/) | Obfuscated Files or Information | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md index 25ef5ddd09..9275ed8c76 100644 --- a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md +++ b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md @@ -37,20 +37,13 @@ DynamicWrapperX is an ActiveX component that can be used in a script to call Win - **ID**: b0a078e4-2601-11ec-9aec-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - | [T1559.001](https://attack.mitre.org/techniques/T1559/001/) | Component Object Model | Execution | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md index 2f6919746b..d26c730a48 100644 --- a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md +++ b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md @@ -34,17 +34,12 @@ This analytic is to detect a suspicious rundll32 commandline to clear shim cache - **ID**: a913718a-25b6-11ec-96d3-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1112](https://attack.mitre.org/techniques/T1112/) | Modify Registry | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md index b6944bd10d..08bad0e9e0 100644 --- a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md +++ b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md @@ -37,20 +37,13 @@ This analytic is to detect a suspicious copy of file from systemroot folder of t - **ID**: ce633e56-25b2-11ec-9e76-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1036.003](https://attack.mitre.org/techniques/T1036/003/) | Rename System Utilities | Defense Evasion | - - - | [T1036](https://attack.mitre.org/techniques/T1036/) | Masquerading | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md index e07315ff09..5cf8996048 100644 --- a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md +++ b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md @@ -35,17 +35,12 @@ The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, - **ID**: d17dae9e-2618-11ec-b9f5-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md index 895ad21f78..371e5c853d 100644 --- a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md +++ b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md @@ -37,20 +37,13 @@ This search allows you to identify DNS requests and compute the standard deviati - **ID**: 1a67f15a-f4ff-4170-84e9-08cf6f75d6f5 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1048.003](https://attack.mitre.org/techniques/T1048/003/) | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | - - - | [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-06-sdelete_application_execution.md b/docs/_posts/2021-10-06-sdelete_application_execution.md index 747f104ad8..12c7160212 100644 --- a/docs/_posts/2021-10-06-sdelete_application_execution.md +++ b/docs/_posts/2021-10-06-sdelete_application_execution.md @@ -40,24 +40,14 @@ This analytic is to detect the execution of sdelete.exe application sysinternal - **ID**: 31702fc0-2682-11ec-85c3-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1485](https://attack.mitre.org/techniques/T1485/) | Data Destruction | Impact | - - | [T1070.004](https://attack.mitre.org/techniques/T1070/004/) | File Deletion | Defense Evasion | - - - | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md index b5534a6cfa..05e564df44 100644 --- a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md +++ b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md @@ -47,28 +47,15 @@ This analytic is to detect a suspicious spawned process by wscript or cscript pr - **ID**: 1f35e1da-267b-11ec-90a9-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - | [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - - | [T1134.004](https://attack.mitre.org/techniques/T1134/004/) | Parent PID Spoofing | Defense Evasion, Privilege Escalation | - - - | [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-07-etw_registry_disabled.md b/docs/_posts/2021-10-07-etw_registry_disabled.md index e7f5bf7607..a0632b76b9 100644 --- a/docs/_posts/2021-10-07-etw_registry_disabled.md +++ b/docs/_posts/2021-10-07-etw_registry_disabled.md @@ -40,24 +40,14 @@ This analytic is to detect a registry modification to disable ETW feature of win - **ID**: 8ed523ac-276b-11ec-ac39-acde48001122 -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1562.006](https://attack.mitre.org/techniques/T1562/006/) | Indicator Blocking | Defense Evasion | - - - | [T1127](https://attack.mitre.org/techniques/T1127/) | Trusted Developer Utilities Proxy Execution | Defense Evasion | - - - | [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md index 25b9dea9c0..0383bb55a1 100644 --- a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md +++ b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md @@ -37,20 +37,13 @@ The wevtutil.exe application is the windows event log utility. This searches for - **ID**: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f -#### ATT&CK +#### [ATT&CK](https://attack.mitre.org/) -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1070.001](https://attack.mitre.org/techniques/T1070/001/) | Clear Windows Event Logs | Defense Evasion | - - - | [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md index 3c9803f410..a8921874a6 100644 --- a/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-10-13-dllhost_with_no_command_line_arguments_with_network.md @@ -35,17 +35,12 @@ The following analytic identifies DLLHost.exe with no command line arguments wit - **ID**: f1c07594-a141-11eb-8407-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md index b1781f7900..ce0952489a 100644 --- a/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md +++ b/docs/_posts/2021-10-13-rundll32_with_no_command_line_arguments_with_network.md @@ -38,20 +38,13 @@ The following analytic identifies rundll32.exe with no command line arguments an - **ID**: 35307032-a12d-11eb-835f-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1218](https://attack.mitre.org/techniques/T1218/) | Signed Binary Proxy Execution | Defense Evasion | - - | [T1218.011](https://attack.mitre.org/techniques/T1218/011/) | Rundll32 | Defense Evasion | - - - - #### Search ``` diff --git a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md index d5551a6cb9..a94ff60f62 100644 --- a/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md +++ b/docs/_posts/2021-10-13-searchprotocolhost_with_no_command_line_with_network.md @@ -35,17 +35,12 @@ The following analytic identifies searchprotocolhost.exe with no command line ar - **ID**: b690df8c-a145-11eb-a38b-acde48001122 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - - - - #### Search ``` diff --git a/docs/_posts/2021-2-1-first_time_seen_command_line_argument.md b/docs/_posts/2021-2-1-first_time_seen_command_line_argument.md index 51544841da..16a59efc04 100644 --- a/docs/_posts/2021-2-1-first_time_seen_command_line_argument.md +++ b/docs/_posts/2021-2-1-first_time_seen_command_line_argument.md @@ -37,25 +37,14 @@ This search looks for command-line arguments that use a `/c` parameter to execut - **ID**: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 -#### ATT&CK - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | +#### [ATT&CK](https://attack.mitre.org/) +| ID | Technique | Tactic | +| ----------- | ----------- | ----------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | - - - | [T1117](https://attack.mitre.org/techniques/T1117/) | Regsvr32 | | - - - | [T1202](https://attack.mitre.org/techniques/T1202/) | Indirect Command Execution | Defense Evasion | - - - - #### Search ``` diff --git a/docs/detections.wiki b/docs/detections.wiki index 3b9e670302..1354ca7f33 100644 --- a/docs/detections.wiki +++ b/docs/detections.wiki @@ -58681,7 +58681,7 @@ There might be false positives associted with this detection since items like ar
 #############
 # Automatically generated by doc_gen.py in https://github.com/splunk/security_content''
-# On Date: 2021-10-27 10:32:03.863986 UTC''
+# On Date: 2021-10-27 16:26:37.924936 UTC''
 # Author: Splunk Security Research''
 # Contact: research@splunk.com''
 #############
diff --git a/docs/stories.wiki b/docs/stories.wiki
index 131ddd59df..6bd3f45390 100644
--- a/docs/stories.wiki
+++ b/docs/stories.wiki
@@ -16463,7 +16463,7 @@ Discovery
 
 #############
 # Automatically generated by doc_gen.py in https://github.com/splunk/security_content
-# On Date: 2021-10-27 10:32:04.194821 UTC
+# On Date: 2021-10-27 16:26:38.301204 UTC
 # Author: Splunk Security Research
 # Contact: research@splunk.com
 #############