mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating detections version
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Detect RClone Command-Line Usage
|
||||
id: 32e0baea-b3f1-11eb-a2ce-acde48001122
|
||||
version: '8'
|
||||
date: '2025-03-03'
|
||||
version: '9'
|
||||
date: '2025-03-27'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Malicious PowerShell Process - Execution Policy Bypass
|
||||
id: 9be56c82-b1cc-4318-87eb-d138afaaca39
|
||||
version: '11'
|
||||
version: '12'
|
||||
date: '2025-02-24'
|
||||
author: Rico Valdez, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Remote Process Instantiation via WMI
|
||||
id: d25d2c3d-d9d8-40ec-8fdf-e86fe155a3da
|
||||
version: '12'
|
||||
date: '2025-02-24'
|
||||
author: Rico Valdez, Mauricio Velazco, Splunk
|
||||
version: '13'
|
||||
date: '2025-03-27'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of wmic.exe with parameters
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Remote Process Instantiation via WMI and PowerShell
|
||||
id: 112638b4-4634-11ec-b9ab-3e22fbd008af
|
||||
version: 13
|
||||
version: 15
|
||||
date: '2025-03-27'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Spoolsv Writing a DLL - Sysmon
|
||||
id: 347fd388-da87-11eb-836d-acde48001122
|
||||
version: '6'
|
||||
date: '2025-03-03'
|
||||
author: Mauricio Velazco, Michael Haag, Splunk
|
||||
version: '7'
|
||||
date: '2025-03-27'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects `spoolsv.exe` writing a `.dll` file, which
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Svchost.exe Parent Process Anomaly
|
||||
id: 1d38e5e9-2ff8-4c47-872c-bf1657cefab5
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2025-02-11'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Unsigned DLL Side-Loading
|
||||
id: 5a83ce44-8e0f-4786-a775-8249a525c879
|
||||
version: '8'
|
||||
version: '9'
|
||||
date: '2025-02-24'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Unsigned DLL Side-Loading In Same Process Path
|
||||
id: 3cf85c02-f9d6-4186-bf3c-e70ee99fbc7f
|
||||
version: 8
|
||||
version: 9
|
||||
date: '2025-02-26'
|
||||
author: Teoderick Contreras, Splunk
|
||||
data_source:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Unsigned MS DLL Side-Loading
|
||||
id: 8d9e0e06-ba71-4dc5-be16-c1a46d58728c
|
||||
version: '8'
|
||||
version: '9'
|
||||
date: '2025-02-24'
|
||||
author: Teoderick Contreras, Splunk
|
||||
data_source:
|
||||
|
||||
Reference in New Issue
Block a user