Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-08-03 08:28:31 -07:00
committed by GitHub
90 changed files with 2395 additions and 1692 deletions
@@ -69,5 +69,3 @@ tags:
- All_Changes.user
risk_score: 36
security_domain: threat
supported_tas:
- Splunk_TA_aws-kinesis-firehose
@@ -69,5 +69,3 @@ tags:
- All_Changes.user
risk_score: 30
security_domain: threat
supported_tas:
- Splunk_TA_aws-kinesis-firehose
@@ -40,7 +40,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Hermetic Wiper
- Hermetic Wiper
confidence: 80
context:
- Source:Endpoint
@@ -76,6 +76,4 @@ tags:
- Registry.registry_value_name
risk_score: 64
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -13,18 +13,18 @@ description: This analytic detects a potential suspicious modification of firewa
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*"
Registry.registry_value_data = "*|Action=Allow|*" Registry.registry_value_data =
"*|Dir=In|*" Registry.registry_value_data = "*|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path
Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data
| `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid,
_time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest
Processes.parent_process_name Processes.parent_process Processes.process_guid |
`drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time
dest user parent_process_name parent_process process_name process_path process proc_guid
registry_path registry_value_name registry_value_data registry_key_name] | table
_time dest user parent_process_name parent_process process_name process_path process
proc_guid registry_path registry_value_name registry_value_data registry_key_name
| `allow_inbound_traffic_by_firewall_rule_registry_filter`'
"*|Dir=In|*" Registry.registry_value_data = "*|LPort=*" by _time span=1h Registry.dest
Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid
Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)`
|rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly`
count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
Processes.process Processes.dest Processes.parent_process_name Processes.parent_process
Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as
proc_guid | fields _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data
registry_key_name] | table _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data
registry_key_name | `allow_inbound_traffic_by_firewall_rule_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
@@ -48,8 +48,8 @@ tags:
impact: 50
kill_chain_phases:
- Exploitation
message: Suspicious firewall allow rule modifications were detected via the registry on endpoint
$dest$ by user $user$.
message: Suspicious firewall allow rule modifications were detected via the registry
on endpoint $dest$ by user $user$.
mitre_attack_id:
- T1021.001
- T1021
@@ -77,6 +77,4 @@ tags:
- Registry.user
risk_score: 25
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -31,7 +31,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -67,6 +67,4 @@ tags:
- Registry.registry_value_name
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -64,8 +64,6 @@ tags:
- Registry.dest
- Registry.registry_value_name
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
confidence: 50
impact: 50
@@ -71,6 +71,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -71,6 +71,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -71,6 +71,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -71,6 +71,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -70,6 +70,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -70,6 +70,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -63,8 +63,6 @@ tags:
- Registry.dest
- Registry.registry_value_name
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
confidence: 50
impact: 50
@@ -68,6 +68,4 @@ tags:
- Registry.registry_value_name
risk_score: 40
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -70,6 +70,4 @@ tags:
- Registry.registry_value_data
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -74,6 +74,4 @@ tags:
- Registry.registry_value_data
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -76,6 +76,4 @@ tags:
- Registry.registry_value_name
risk_score: 40
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -72,6 +72,4 @@ tags:
- Registry.registry_value_name
risk_score: 25
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -71,6 +71,4 @@ tags:
- Registry.registry_value_name
risk_score: 25
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -72,6 +72,4 @@ tags:
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -75,6 +75,4 @@ tags:
- Registry.registry_value_name
risk_score: 25
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -75,6 +75,4 @@ tags:
- Registry.registry_value_name
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -73,6 +73,4 @@ tags:
- Registry.registry_value_name
risk_score: 42
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -68,6 +68,4 @@ tags:
- Registry.registry_value_name
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -75,6 +75,4 @@ tags:
- Registry.registry_value_data
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -38,7 +38,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -76,6 +76,4 @@ tags:
- Registry.registry_value_data
risk_score: 90
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -79,6 +79,4 @@ tags:
- Registry.registry_value_name
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -35,7 +35,7 @@ references:
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
tags:
analytic_story:
- Double Zero Destructor
- Double Zero Destructor
- Data Destruction
- XMRig
- Remcos
@@ -85,6 +85,4 @@ tags:
- Filesystem.user
risk_score: 56
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -28,7 +28,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Hermetic Wiper
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -64,6 +64,4 @@ tags:
- Registry.registry_value_name
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -74,3 +74,5 @@ tags:
- Processes.parent_process_name
risk_score: 36
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -55,8 +55,6 @@ tags:
- Filesystem.user
- Filesystem.file_path
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
confidence: 50
impact: 50
@@ -9,8 +9,7 @@ datamodel:
description: The search looks for modifications to registry keys that can be used
to launch an application or service at system startup.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Registry
where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce
as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce
OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls*
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify*
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet*
@@ -24,13 +23,10 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion"
AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session
Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run"
AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `registry_keys_used_for_persistence_filter`'
AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user Registry.registry_path
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
Registry.registry_key_name | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `registry_keys_used_for_persistence_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
@@ -95,5 +91,3 @@ tags:
- Registry.user
risk_score: 76
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -62,6 +62,4 @@ tags:
- Registry.user
risk_score: 90
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -71,6 +71,4 @@ tags:
- Registry.registry_key_name
risk_score: 60
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -86,3 +86,5 @@ tags:
- Processes.parent_process_name
risk_score: 36
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -65,4 +65,6 @@ tags:
- Processes.parent_process_id
risk_score: 25
security_domain: endpoint
asset_type: Endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -82,3 +82,5 @@ tags:
- Processes.parent_process_id
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -59,3 +59,5 @@ tags:
- Filesystem.user
risk_score: 70
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -32,7 +32,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
- Hermetic Wiper
confidence: 90
context:
- Source:Endpoint
@@ -68,6 +68,4 @@ tags:
- Registry.registry_value_name
risk_score: 72
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -4,7 +4,7 @@ version: 3
date: '2020-12-08'
author: David Dorsey, Splunk
type: TTP
datamodel:
datamodel:
- Endpoint
description: This search looks for shim database files being written to default directories.
The sdbinst.exe application is used to install shim database files (.sdb). According
@@ -66,3 +66,5 @@ tags:
- Filesystem.dest
risk_score: 56
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -94,5 +94,3 @@ tags:
- cmd_line
risk_score: 56
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -4,7 +4,7 @@ version: 4
date: '2020-07-22'
author: Rico Valdez, Splunk
type: TTP
datamodel:
datamodel:
- Endpoint
description: This search detects writes to the recycle bin by a process other than
explorer.exe.
@@ -70,3 +70,5 @@ tags:
security_domain: endpoint
kill_chain_phases:
- Exploitation
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -39,7 +39,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -75,6 +75,4 @@ tags:
- Registry.registry_value_name
risk_score: 80
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -6,23 +6,31 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL).
In addition to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an import table entry consisting of the specified DLL into the module at the given base address.
During triage, review file modifcations and parallel processes.
description: Adversaries may abuse mavinject.exe to inject malicious DLLs into running
processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution
(ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL). In addition
to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import
descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe
PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an
import table entry consisting of the specified DLL into the module at the given
base address. During triage, review file modifcations and parallel processes.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mavinject.exe Processes.process IN ("*injectrunning*", "*hmodule=0x*")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_binary_proxy_execution_mavinject_dll_injection_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present, filter on DLL name or parent process.
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mavinject.exe
Processes.process IN ("*injectrunning*", "*hmodule=0x*") by Processes.dest Processes.user
Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_binary_proxy_execution_mavinject_dll_injection_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present, filter on DLL name or parent
process.
references:
- https://attack.mitre.org/techniques/T1218/013/
- https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-1---mavinject---inject-dll-into-running-process
- https://attack.mitre.org/techniques/T1218/013/
- https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-1---mavinject---inject-dll-into-running-process
tags:
analytic_story:
- Living Off The Land
@@ -40,7 +48,8 @@ tags:
impact: 70
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting load a DLL.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting load a DLL.
mitre_attack_id:
- T1218.013
- T1218
@@ -71,14 +80,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,23 +6,25 @@ author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies path traversal command-line execution. This technique was seen in malicious document that execute malicious code
using msdt.exe and path traversal technique that serve as defense evasion. This TTP is a good pivot to look for more suspicious process and command-line
that runs before and after this execution. This may help you to find possible downloaded malware or other lolbin execution.
description: The following analytic identifies path traversal command-line execution.
This technique was seen in malicious document that execute malicious code using
msdt.exe and path traversal technique that serve as defense evasion. This TTP is
a good pivot to look for more suspicious process and command-line that runs before
and after this execution. This may help you to find possible downloaded malware
or other lolbin execution.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/*" OR Processes.process="*\\..\\..\\..\\*" OR Processes.process="*\/\/..\/\/..\/\/..\/\/*" by
Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process
Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash
| `drop_dm_object_name("Processes")`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_command_and_scripting_interpreter_path_traversal_exec_filter`'
as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/*"
OR Processes.process="*\\..\\..\\..\\*" OR Processes.process="*\/\/..\/\/..\/\/..\/\/*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id
Processes.process_hash | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_command_and_scripting_interpreter_path_traversal_exec_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product
known_false_positives: Not known at this moment.
known_false_positives: Not known at this moment.
references:
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
tags:
@@ -43,7 +45,8 @@ tags:
impact: 90
kill_chain_phases:
- Exploitation
message: A parent process $parent_process_name$ has spawned a child $process_name$ with path traversal commandline $process$ in $dest$
message: A parent process $parent_process_name$ has spawned a child $process_name$
with path traversal commandline $process$ in $dest$
mitre_attack_id:
- T1059
nist:
@@ -61,14 +64,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 90
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,19 +6,23 @@ author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies DCRat "forkbomb" payload feature.
This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process
executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script
in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.parent_process_id) as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name= "notepad.exe") Processes.parent_process = "*.bat*"
by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest Processes.user _time
span=30s | where parent_process_id_count>= 10 AND process_id_count >=10
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_command_shell_dcrat_forkbomb_payload_filter`'
description: The following analytic identifies DCRat "forkbomb" payload feature. This
technique was seen in dark crystal RAT backdoor capabilities where it will execute
several cmd child process executing "notepad.exe & pause". This analytic detects
the multiple cmd.exe and child process notepad.exe execution using batch script
in the targeted host within 30s timeframe. this TTP can be a good pivot to check
DCRat infection.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.parent_process) as parent_process values(Processes.parent_process_id)
as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id)
as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time)
as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=
"cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name=
"notepad.exe") Processes.parent_process = "*.bat*" by Processes.parent_process_name
Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest
Processes.user _time span=30s | where parent_process_id_count>= 10 AND process_id_count
>=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |
`security_content_ctime(lastTime)` | `windows_command_shell_dcrat_forkbomb_payload_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
@@ -45,7 +49,8 @@ tags:
impact: 90
kill_chain_phases:
- Exploitation
message: Multiple cmd.exe processes with child process of notepad.exe executed on $dest$
message: Multiple cmd.exe processes with child process of notepad.exe executed on
$dest$
mitre_attack_id:
- T1059.003
- T1059
@@ -75,3 +80,5 @@ tags:
- Processes.parent_process_id
risk_score: 81
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -75,6 +75,4 @@ tags:
- Registry.registry_value_data
risk_score: 64
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint
@@ -6,13 +6,15 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to detect a suspicious registry modification to disable Lock Computer windows features.
This registry modification prevent the user from locking its screen or computer that are being abused by several malware for example ransomware.
This technique was used by threat actor to make its payload more impactful to the compromised host.
description: This analytic is to detect a suspicious registry modification to disable
Lock Computer windows features. This registry modification prevent the user from
locking its screen or computer that are being abused by several malware for example
ransomware. This technique was used by threat actor to make its payload more impactful
to the compromised host.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation"
Registry.registry_value_data = "0x00000001"
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
@@ -21,15 +23,14 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint
proc_guid | fields _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data]
| table _time dest user parent_process_name parent_process process_name process_path
process proc_guid registry_path registry_value_name registry_value_data
| `windows_disable_lock_workstation_feature_through_registry_filter`'
process proc_guid registry_path registry_value_name registry_value_data | `windows_disable_lock_workstation_feature_through_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
known_false_positives: unknown
references:
- https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/
- https://heimdalsecurity.com/blog/fatalrat-targets-telegram/
- https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/
- https://heimdalsecurity.com/blog/fatalrat-targets-telegram/
tags:
analytic_story:
- Ransomware
@@ -51,17 +52,16 @@ tags:
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
- Processes.process_id
- Processes.process_id
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_guid
- Processes.process_guid
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
confidence: 70
risk_score: 49
context:
- Source:Endpoint
@@ -78,4 +78,6 @@ tags:
- CIS 3
- CIS 5
- CIS 16
asset_type: Endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,33 +6,35 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to detect a suspicious registry modification to disable logoff feature in windows host.
This registry when enable will prevent users to log off of the system by using any method,
including programs run from the command line, such as scripts. It also disables or removes
all menu items and buttons that log the user off of the system. This technique was seen abused by ransomware malware
to make the compromised host un-useful and hard to remove other registry modification made on the machine that needs restart to take effect.
This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
and users that can modify this registry is needed.
description: This analytic is to detect a suspicious registry modification to disable
logoff feature in windows host. This registry when enable will prevent users to
log off of the system by using any method, including programs run from the command
line, such as scripts. It also disables or removes all menu items and buttons that
log the user off of the system. This technique was seen abused by ransomware malware
to make the compromised host un-useful and hard to remove other registry modification
made on the machine that needs restart to take effect. This windows feature may
implement by administrator in some server where shutdown is critical. In that scenario
filter of machine and users that can modify this registry is needed.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff")
Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
Processes.process Processes.dest Processes.parent_process_name Processes.parent_process
Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as
proc_guid | fields _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data]
| table _time dest user parent_process_name parent_process process_name process_path
process proc_guid registry_path registry_value_name registry_value_data
| `windows_disable_logoff_button_through_registry_filter`'
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff") Registry.registry_value_data
= "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
| `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid,
_time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest
Processes.parent_process_name Processes.parent_process Processes.process_guid |
`drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time
dest user parent_process_name parent_process process_name process_path process proc_guid
registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name
parent_process process_name process_path process proc_guid registry_path registry_value_name
registry_value_data | `windows_disable_logoff_button_through_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
known_false_positives: This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
and users that can modify this registry is needed.
known_false_positives: This windows feature may implement by administrator in some
server where shutdown is critical. In that scenario filter of machine and users
that can modify this registry is needed.
references:
- https://www.hybrid-analysis.com/sample/e2d4018fd3bd541c153af98ef7c25b2bf4a66bc3bfb89e437cde89fd08a9dd7b/5b1f4d947ca3e10f22714774
- https://malwiki.org/index.php?title=DigiPop.xp
@@ -57,17 +59,16 @@ tags:
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
- Processes.process_id
- Processes.process_id
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_guid
- Processes.process_guid
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
confidence: 70
risk_score: 49
context:
- Source:Endpoint
@@ -84,4 +85,6 @@ tags:
- CIS 3
- CIS 5
- CIS 16
asset_type: Endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,16 +6,18 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to detect a suspicious registry modification to disable shutdown button on the logon user.
This technique was seen in several malware especially in ransomware family like killdisk malware variant to make the compromised host
un-useful and hard to remove other registry modification made on the machine that needs restart to take effect.
This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
and users that can modify this registry is needed.
description: This analytic is to detect a suspicious registry modification to disable
shutdown button on the logon user. This technique was seen in several malware especially
in ransomware family like killdisk malware variant to make the compromised host
un-useful and hard to remove other registry modification made on the machine that
needs restart to take effect. This windows feature may implement by administrator
in some server where shutdown is critical. In that scenario filter of machine and
users that can modify this registry is needed.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\shutdownwithoutlogon"
Registry.registry_value_data = "0x00000000")
OR (Registry.registry_path="*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoClose" Registry.registry_value_data = "0x00000001")
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.registry_value_data = "0x00000000") OR (Registry.registry_path="*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoClose"
Registry.registry_value_data = "0x00000001") by _time span=1h Registry.dest Registry.user
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
@@ -24,15 +26,15 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint
proc_guid | fields _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data]
| table _time dest user parent_process_name parent_process process_name process_path
process proc_guid registry_path registry_value_name registry_value_data
| `windows_disable_shutdown_button_through_registry_filter`'
process proc_guid registry_path registry_value_name registry_value_data | `windows_disable_shutdown_button_through_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
known_false_positives: This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
and users that can modify this registry is needed.
known_false_positives: This windows feature may implement by administrator in some
server where shutdown is critical. In that scenario filter of machine and users
that can modify this registry is needed.
references:
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.msil.screenlocker.a/
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.msil.screenlocker.a/
tags:
analytic_story:
- Ransomware
@@ -53,17 +55,16 @@ tags:
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
- Processes.process_id
- Processes.process_id
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_guid
- Processes.process_guid
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
confidence: 70
risk_score: 49
context:
- Source:Endpoint
@@ -80,4 +81,6 @@ tags:
- CIS 3
- CIS 5
- CIS 16
asset_type: Endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,16 +6,20 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to detect a suspicious registry modification to disable windows features.
These techniques are seen in several ransomware malware to impair the compromised host to make it hard for analyst to mitigate or response
from the attack. Disabling these known features make the analysis and forensic response more hard. Disabling these feature is not so common but
can still be implemented by the administrator for security purposes. In this scenario filters for users that are allowed doing this is needed.
description: This analytic is to detect a suspicious registry modification to disable
windows features. These techniques are seen in several ransomware malware to impair
the compromised host to make it hard for analyst to mitigate or response from the
attack. Disabling these known features make the analysis and forensic response more
hard. Disabling these feature is not so common but can still be implemented by the
administrator for security purposes. In this scenario filters for users that are
allowed doing this is needed.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\*"
Registry.registry_value_name IN ("NoDesktop", "NoFind", "NoControlPanel", "NoFileMenu", "NoSetTaskbar", "NoTrayContextMenu",
"TaskbarLockAll", "NoThemesTab","NoPropertiesMyDocuments","NoVisualStyleChoice","NoColorChoice","NoPropertiesMyDocuments")
Registry.registry_value_data = "0x00000001"
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\*"
Registry.registry_value_name IN ("NoDesktop", "NoFind", "NoControlPanel", "NoFileMenu",
"NoSetTaskbar", "NoTrayContextMenu", "TaskbarLockAll", "NoThemesTab","NoPropertiesMyDocuments","NoVisualStyleChoice","NoColorChoice","NoPropertiesMyDocuments")
Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
@@ -24,8 +28,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint
proc_guid | fields _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data]
| table _time dest user parent_process_name parent_process process_name process_path
process proc_guid registry_path registry_value_name registry_value_data
| `windows_disable_windows_group_policy_features_through_registry_filter`'
process proc_guid registry_path registry_value_name registry_value_data | `windows_disable_windows_group_policy_features_through_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
@@ -55,17 +58,16 @@ tags:
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
- Processes.process_id
- Processes.process_id
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_guid
- Processes.process_guid
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
confidence: 70
risk_score: 49
context:
- Source:Endpoint
@@ -82,4 +84,6 @@ tags:
- CIS 3
- CIS 5
- CIS 16
asset_type: Endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -69,5 +69,3 @@ tags:
- Registry.registry_path
risk_score: 24
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,24 +6,33 @@ author: Michael Haag, Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies a recently disclosed arbitraty command execution using Windows msdt.exe - a Diagnostics Troubleshooting Wizard. The sample identified will use the ms-msdt:/ protocol handler to load msdt.exe to retrieve a remote payload.
During triage, review file modifications for html. Identify parallel process execution that may be related, including an Office Product.
description: The following analytic identifies a recently disclosed arbitraty command
execution using Windows msdt.exe - a Diagnostics Troubleshooting Wizard. The sample
identified will use the ms-msdt:/ protocol handler to load msdt.exe to retrieve
a remote payload. During triage, review file modifications for html. Identify parallel
process execution that may be related, including an Office Product.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msdt.exe
Processes.process IN ("*msdt*","*ms-msdt:*","*ms-msdt:/id*","*ms-msdt:-id*","*/id*") AND (Processes.process="*IT_BrowseForFile=*" OR Processes.process="*IT_RebrowseForFile=*" OR Processes.process="*.xml*") AND Processes.process="*PCWDiagnostic*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`| `windows_execute_arbitrary_commands_with_msdt_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present, filter as needed. Added .xml to potentially capture any answer file usage. Remove as needed.
Processes.process IN ("*msdt*","*ms-msdt:*","*ms-msdt:/id*","*ms-msdt:-id*","*/id*")
AND (Processes.process="*IT_BrowseForFile=*" OR Processes.process="*IT_RebrowseForFile=*"
OR Processes.process="*.xml*") AND Processes.process="*PCWDiagnostic*" by Processes.dest
Processes.user Processes.parent_process_name Processes.process_name Processes.process
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `windows_execute_arbitrary_commands_with_msdt_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present, filter as needed. Added .xml
to potentially capture any answer file usage. Remove as needed.
references:
- https://isc.sans.edu/diary/rss/28694
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
- https://isc.sans.edu/diary/rss/28694
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
tags:
analytic_story:
- Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190
@@ -43,8 +52,8 @@ tags:
impact: 100
kill_chain_phases:
- Exploitation
message: A parent process $parent_process_name$ has spawned a child
process $process_name$ on host $dest$ possibly indicative of indirect command execution.
message: A parent process $parent_process_name$ has spawned a child process $process_name$
on host $dest$ possibly indicative of indirect command execution.
mitre_attack_id:
- T1218
nist:
@@ -74,14 +83,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 100
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,30 +6,32 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to detect a suspicious registry modification to hide common windows notification feature from compromised host.
This technique was seen in some ransomware family to add more impact to its payload that are visually seen by user aside from the encrypted files and
ransomware notes. Even this a good anomaly detection, administrator may implement this changes for auditing or security reason. In this scenario filter is needed.
description: This analytic is to detect a suspicious registry modification to hide
common windows notification feature from compromised host. This technique was seen
in some ransomware family to add more impact to its payload that are visually seen
by user aside from the encrypted files and ransomware notes. Even this a good anomaly
detection, administrator may implement this changes for auditing or security reason.
In this scenario filter is needed.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
Registry.registry_value_name IN ("HideClock", "HideSCAHealth", "HideSCANetwork", "HideSCAPower", "HideSCAVolume")
Registry.registry_value_data = "0x00000001"
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
Registry.registry_value_name IN ("HideClock", "HideSCAHealth", "HideSCANetwork",
"HideSCAPower", "HideSCAVolume") Registry.registry_value_data = "0x00000001" by
_time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly`
count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
Processes.process Processes.dest Processes.parent_process_name Processes.parent_process
Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as
proc_guid | fields _time dest user parent_process_name parent_process process_name
process_path process proc_guid registry_path registry_value_name registry_value_data]
| table _time dest user parent_process_name parent_process process_name process_path
process proc_guid registry_path registry_value_name registry_value_data
| `windows_hide_notification_features_through_registry_filter`'
process proc_guid registry_path registry_value_name registry_value_data | `windows_hide_notification_features_through_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
known_false_positives: unknown
references:
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom.Win32.ONALOCKER.A/
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom.Win32.ONALOCKER.A/
tags:
analytic_story:
- Ransomware
@@ -51,17 +53,16 @@ tags:
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
- Processes.process_id
- Processes.process_id
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.process
- Processes.dest
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_guid
- Processes.process_guid
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
confidence: 70
risk_score: 49
context:
- Source:Endpoint
@@ -78,4 +79,6 @@ tags:
- CIS 3
- CIS 5
- CIS 16
asset_type: Endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,19 +6,18 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The search looks for the deletion of Windows Defender main profile within the registry.
This was used by RAT malware across a fleet of endpoints. This particular
behavior is typically executed when an adversary gains access to an endpoint
and beings to perform execution. Usually, a batch (.bat) will be executed and multiple
description: The search looks for the deletion of Windows Defender main profile within
the registry. This was used by RAT malware across a fleet of endpoints. This particular
behavior is typically executed when an adversary gains access to an endpoint and
beings to perform execution. Usually, a batch (.bat) will be executed and multiple
registry and scheduled task modifications will occur. During triage, review parallel
processes and identify any further file modifications.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender" Registry.action = deleted
by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.user Registry.dest
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_impair_defense_delete_win_defender_profile_registry_filter`'
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows
Defender" Registry.action = deleted by Registry.registry_path Registry.registry_value_name
Registry.registry_value_data Registry.process_guid Registry.action Registry.user
Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_impair_defense_delete_win_defender_profile_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node.
@@ -71,5 +70,3 @@ tags:
- Registry.action
risk_score: 64
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -7,24 +7,28 @@ type: TTP
datamodel:
- Endpoint
description: The following analytic identifies a modification in the Windows registry
by the Applocker utility that contains details or registry data values related to denying the execution of several security products.
This technique was seen in Azorult malware where it drops an xml Applocker policy that will deny several AV products and then loaded by using PowerShell Applocker
commandlet.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group Policy Objects\\*" AND Registry.registry_path= "*}Machine\\Software\\Policies\\Microsoft\\Windows\\SrpV2*")
OR Registry.registry_path="*\\Software\\Policies\\Microsoft\\Windows\\SrpV2*"
AND Registry.registry_value_data = "*Action\=\"Deny\"*"
AND Registry.registry_value_data IN("*O=SYMANTEC*","*O=MCAFEE*","*O=KASPERSKY*","*O=BLEEPING COMPUTER*", "*O=PANDA SECURITY*","*O=SYSTWEAK SOFTWARE*", "*O=TREND MICRO*", "*O=AVAST*", "*O=GRIDINSOFT*", "*O=MICROSOFT*", "*O=NANO SECURITY*", "*O=SUPERANTISPYWARE.COM*", "*O=DOCTOR WEB*", "*O=MALWAREBYTES*", "*O=ESET*", "*O=AVIRA*", "*O=WEBROOT*")
by Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.registry_key_name Registry.dest
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
by the Applocker utility that contains details or registry data values related to
denying the execution of several security products. This technique was seen in Azorult
malware where it drops an xml Applocker policy that will deny several AV products
and then loaded by using PowerShell Applocker commandlet.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group
Policy Objects\\*" AND Registry.registry_path= "*}Machine\\Software\\Policies\\Microsoft\\Windows\\SrpV2*")
OR Registry.registry_path="*\\Software\\Policies\\Microsoft\\Windows\\SrpV2*" AND
Registry.registry_value_data = "*Action\=\"Deny\"*" AND Registry.registry_value_data
IN("*O=SYMANTEC*","*O=MCAFEE*","*O=KASPERSKY*","*O=BLEEPING COMPUTER*", "*O=PANDA
SECURITY*","*O=SYSTWEAK SOFTWARE*", "*O=TREND MICRO*", "*O=AVAST*", "*O=GRIDINSOFT*",
"*O=MICROSOFT*", "*O=NANO SECURITY*", "*O=SUPERANTISPYWARE.COM*", "*O=DOCTOR WEB*",
"*O=MALWAREBYTES*", "*O=ESET*", "*O=AVIRA*", "*O=WEBROOT*") by Registry.user Registry.registry_path
Registry.registry_value_data Registry.action Registry.registry_key_name Registry.dest
| `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_impair_defense_deny_security_software_with_applocker_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
that this registry was included in your config files ex. sysmon config to be monitored.
known_false_positives: False positives may be present based on organization use of Applocker. Filter as needed.
known_false_positives: False positives may be present based on organization use of
Applocker. Filter as needed.
references:
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
- https://www.microsoftpressstore.com/articles/article.aspx?p=2228450&seqNum=11
@@ -45,9 +49,10 @@ tags:
impact: 100
kill_chain_phases:
- Exploitation
message: Applocker registry modification to deny the action of several AV products on $dest$.
message: Applocker registry modification to deny the action of several AV products
on $dest$.
mitre_attack_id:
- T1562.001
- T1562.001
- T1562
nist:
- DE.CM
@@ -74,4 +79,6 @@ tags:
- Processes.process_path
- Processes.parent_process_id
risk_score: 100
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,19 +6,18 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The search looks for the Registry Key DefenderApiLogger or DefenderAuditLogger set to disable.
This is consistent with RAT malware across a fleet of endpoints. This particular
behavior is typically executed when an adversary gains access to an endpoint
and beings to perform execution. Usually, a batch (.bat) will be executed and multiple
registry and scheduled task modifications will occur. During triage, review parallel
processes and identify any further file modifications.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where (Registry.registry_path = "*WMI\\Autologger\\DefenderApiLogger\\Start" OR Registry.registry_path = "*WMI\\Autologger\\DefenderAuditLogger\\Start") Registry.registry_value_data ="0x00000000"
by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.dest Registry.user
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_impair_defenses_disable_win_defender_auto_logging_filter`'
description: The search looks for the Registry Key DefenderApiLogger or DefenderAuditLogger
set to disable. This is consistent with RAT malware across a fleet of endpoints.
This particular behavior is typically executed when an adversary gains access to
an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed
and multiple registry and scheduled task modifications will occur. During triage,
review parallel processes and identify any further file modifications.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path = "*WMI\\Autologger\\DefenderApiLogger\\Start"
OR Registry.registry_path = "*WMI\\Autologger\\DefenderAuditLogger\\Start") Registry.registry_value_data
="0x00000000" by Registry.registry_path Registry.registry_value_name Registry.registry_value_data
Registry.process_guid Registry.action Registry.dest Registry.user | `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_impair_defenses_disable_win_defender_auto_logging_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node.
@@ -71,5 +70,3 @@ tags:
- Registry.action
risk_score: 24
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -7,25 +7,25 @@ type: TTP
datamodel:
- Endpoint
description: The following analytic detects programs that have been started by forfiles.exe.
According to Microsoft, the 'The forfiles command lets you run a command on or pass
According to Microsoft, the 'The forfiles command lets you run a command on or pass
arguments to multiple files'. While this tool can be used to start legitimate programs,
usually within the context of a batch script, it has been observed being used to evade
protections on command line execution.
usually within the context of a batch script, it has been observed being used to
evade protections on command line execution.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*forfiles* /c *"
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_path
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_indirect_command_execution_via_forfiles_filter`'
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*forfiles*
/c *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
Processes.process_path | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_indirect_command_execution_via_forfiles_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the full process path in the process field of CIM's Process data model.
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
Tune and filter known instances where forfiles.exe may be used.
known_false_positives: Some legacy applications may be run using pcalua.exe.
Similarly, forfiles.exe may be used in legitimate batch scripts. Filter these results as needed.
known_false_positives: Some legacy applications may be run using pcalua.exe. Similarly,
forfiles.exe may be used in legitimate batch scripts. Filter these results as needed.
references:
- https://twitter.com/KyleHanslovan/status/912659279806640128
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/forfiles
- https://twitter.com/KyleHanslovan/status/912659279806640128
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/forfiles
tags:
analytic_story:
- Living Off The Land
@@ -43,21 +43,20 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
- Processes.process_path
security_domain: endpoint
impact: 50
confidence: 50
# (impact * confidence)/100
confidence: 50
risk_score: 25
context:
context:
- Source:Endpoint
- Stage:Defense Evasion
message: The Program Compatability Assistant (pcalua.exe) launched the process $process_name$
@@ -70,5 +69,7 @@ tags:
- DE.AE
cis20:
- CIS 8
- CIS 10
- CIS 10
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,24 +6,25 @@ author: Eric McGinnis, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic detects programs that have been started by pcalua.exe.
pcalua.exe is the Microsoft Windows Program Compatability Assistant. While this tool
can be used to start legitimate programs, it has been observed being used to evade
protections on command line execution.
description: The following analytic detects programs that have been started by pcalua.exe.
pcalua.exe is the Microsoft Windows Program Compatability Assistant. While this
tool can be used to start legitimate programs, it has been observed being used to
evade protections on command line execution.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*pcalua* -a*"
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_path
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_indirect_command_execution_via_pcalua_filter`'
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*pcalua*
-a*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
Processes.process_path | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_indirect_command_execution_via_pcalua_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the full process path in the process field of CIM's Process data model.
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
Tune and filter known instances where pcalua.exe may be used.
known_false_positives: Some legacy applications may be run using pcalua.exe. Filter these results as needed.
known_false_positives: Some legacy applications may be run using pcalua.exe. Filter
these results as needed.
references:
- https://twitter.com/KyleHanslovan/status/912659279806640128
- https://lolbas-project.github.io/lolbas/Binaries/Pcalua/
- https://twitter.com/KyleHanslovan/status/912659279806640128
- https://lolbas-project.github.io/lolbas/Binaries/Pcalua/
tags:
analytic_story:
- Living Off The Land
@@ -41,21 +42,20 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
- Processes.process_path
security_domain: endpoint
impact: 50
confidence: 50
# (impact * confidence)/100
confidence: 50
risk_score: 25
context:
context:
- Source:Endpoint
- Stage:Defense Evasion
message: The Program Compatability Assistant (pcalua.exe) launched the process $process_name$
@@ -68,5 +68,7 @@ tags:
- DE.AE
cis20:
- CIS 8
- CIS 10
- CIS 10
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,24 +6,27 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies modification of Windows registry
using regedit.exe application with silent mode parameter. regedit.exe windows application is commonly used as GUI app to check or modify registry.
This application is also has undocumented command-line parameter and one of those are silent mode parameter that performs action without stopping for confirmation with
dialog box. Importing registry from .reg files need to monitor in a production environment since it can be used adversaries to import RMS registry in compromised host.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name="regedit.exe" OR Processes.original_file_name="regedit.exe")
AND Processes.process="* /s *" AND Processes.process="*.reg*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_modify_registry_regedit_silent_reg_import_filter`'
description: The following analytic identifies modification of Windows registry using
regedit.exe application with silent mode parameter. regedit.exe windows application
is commonly used as GUI app to check or modify registry. This application is also
has undocumented command-line parameter and one of those are silent mode parameter
that performs action without stopping for confirmation with dialog box. Importing
registry from .reg files need to monitor in a production environment since it can
be used adversaries to import RMS registry in compromised host.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name="regedit.exe" OR Processes.original_file_name="regedit.exe")
AND Processes.process="* /s *" AND Processes.process="*.reg*" by Processes.dest
Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_modify_registry_regedit_silent_reg_import_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Administrators may execute this command that may cause some false positive. Filter as needed.
known_false_positives: Administrators may execute this command that may cause some
false positive. Filter as needed.
references:
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
- https://www.techtarget.com/searchwindowsserver/tip/Command-line-options-for-Regeditexe
@@ -44,7 +47,8 @@ tags:
impact: 70
kill_chain_phases:
- Exploitation
message: The regedit app was executed with silet mode parameter to import .reg file on $dest$.
message: The regedit app was executed with silet mode parameter to import .reg file
on $dest$.
mitre_attack_id:
- T1112
nist:
@@ -72,4 +76,6 @@ tags:
- Processes.process_path
- Processes.parent_process_id
risk_score: 49
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -74,3 +74,5 @@ tags:
risk_score: 25
security_domain: endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,27 +6,34 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following anaytic identifies MOFComp.exe loading a MOF file. The Managed Object Format (MOF) compiler parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository.
Typically, MOFComp.exe does not reach out to the public internet or load a MOF file from User Profile paths.
A filter and consumer is typically registered in WMI. Review parallel processes and query WMI subscriptions to gather artifacts.
The default path of mofcomp.exe is C:\Windows\System32\wbem.
description: The following anaytic identifies MOFComp.exe loading a MOF file. The
Managed Object Format (MOF) compiler parses a file containing MOF statements and
adds the classes and class instances defined in the file to the WMI repository.
Typically, MOFComp.exe does not reach out to the public internet or load a MOF file
from User Profile paths. A filter and consumer is typically registered in WMI. Review
parallel processes and query WMI subscriptions to gather artifacts. The default
path of mofcomp.exe is C:\Windows\System32\wbem.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where
(Processes.parent_process_name IN ("cmd.exe", "powershell.exe") Processes.process_name=mofcomp.exe)
OR (Processes.process_name=mofcomp.exe Processes.process IN ("*\\AppData\\Local\\*","*\\Users\\Public\\*", "*\\WINDOWS\\Temp\\*"))
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_mof_event_triggered_execution_via_wmi_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present from automation based applications (SCCM), filtering may be required. In addition, break the query out based on volume of usage. Filter process names or f
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name
IN ("cmd.exe", "powershell.exe") Processes.process_name=mofcomp.exe) OR (Processes.process_name=mofcomp.exe
Processes.process IN ("*\\AppData\\Local\\*","*\\Users\\Public\\*", "*\\WINDOWS\\Temp\\*"))
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_mof_event_triggered_execution_via_wmi_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present from automation based applications
(SCCM), filtering may be required. In addition, break the query out based on volume
of usage. Filter process names or f
references:
- https://attack.mitre.org/techniques/T1546/003/
- https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
- https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp
- https://pentestlab.blog/2020/01/21/persistence-wmi-event-subscription/
- https://www.sakshamdixit.com/wmi-events/
- https://attack.mitre.org/techniques/T1546/003/
- https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
- https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp
- https://pentestlab.blog/2020/01/21/persistence-wmi-event-subscription/
- https://www.sakshamdixit.com/wmi-events/
tags:
analytic_story:
- Living Off The Land
@@ -44,7 +51,8 @@ tags:
impact: 80
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ loading a MOF file.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ loading a MOF file.
mitre_attack_id:
- T1546.003
nist:
@@ -74,14 +82,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 64
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,21 +6,25 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies the usage of msiexec.exe using the /y switch parameter, which grants the ability for msiexec to load DLLRegisterServer.
description: The following analytic identifies the usage of msiexec.exe using the
/y switch parameter, which grants the ability for msiexec to load DLLRegisterServer.
Upon triage, review parent process and capture any artifacts for further review.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where `process_msiexec`
Processes.process IN ("*/y*", "*-y*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_msiexec_dllregisterserver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: This analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. Filter as needed.
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process
IN ("*/y*", "*-y*") by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_msiexec_dllregisterserver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: This analytic will need to be tuned for your environment based
on legitimate usage of msiexec.exe. Filter as needed.
references:
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
tags:
analytic_story:
- Windows System Binary Proxy Execution MSIExec
@@ -38,7 +42,8 @@ tags:
impact: 70
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to register a file.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to register a file.
mitre_attack_id:
- T1218.007
nist:
@@ -68,14 +73,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 35
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,21 +6,25 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies msiexec.exe with http in the command-line. This procedure will utilize msiexec.exe to download a remote file and load it.
During triage, review parallel processes and capture any artifacts on disk for review.
description: The following analytic identifies msiexec.exe with http in the command-line.
This procedure will utilize msiexec.exe to download a remote file and load it. During
triage, review parallel processes and capture any artifacts on disk for review.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process IN ("*http://*", "*https://*")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_msiexec_remote_download_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present, filter by destination or parent process as needed.
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process
IN ("*http://*", "*https://*") by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_msiexec_remote_download_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present, filter by destination or parent
process as needed.
references:
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
tags:
analytic_story:
- Windows System Binary Proxy Execution MSIExec
@@ -38,7 +42,8 @@ tags:
impact: 70
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a remote file.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to download a remote file.
mitre_attack_id:
- T1218.007
nist:
@@ -68,14 +73,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 35
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,20 +6,27 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies MSIExec spawning multiple discovery commands, including spawning Cmd.exe or PowerShell.exe. Typically, child processes are not common from MSIExec other than MSIExec spawning itself.
description: The following analytic identifies MSIExec spawning multiple discovery
commands, including spawning Cmd.exe or PowerShell.exe. Typically, child processes
are not common from MSIExec other than MSIExec spawning itself.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=msiexec.exe Processes.process_name IN ("powershell.exe","cmd.exe", "nltest.exe","ipconfig.exe","systeminfo.exe")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=msiexec.exe
Processes.process_name IN ("powershell.exe","cmd.exe", "nltest.exe","ipconfig.exe","systeminfo.exe")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_msiexec_spawn_discovery_command_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives will be present with MSIExec spawning Cmd or PowerShell. Filtering will be needed. In addition, add other known discovery processes to enhance query.
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives will be present with MSIExec spawning Cmd or
PowerShell. Filtering will be needed. In addition, add other known discovery processes
to enhance query.
references:
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
tags:
analytic_story:
- Windows System Binary Proxy Execution MSIExec
@@ -37,7 +44,8 @@ tags:
impact: 70
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running different discovery commands.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ running different discovery commands.
mitre_attack_id:
- T1218.007
nist:
@@ -67,14 +75,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 35
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,20 +6,25 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies the usage of msiexec.exe using the /z switch parameter, which grants the ability for msiexec to unload DLLRegisterServer.
description: The following analytic identifies the usage of msiexec.exe using the
/z switch parameter, which grants the ability for msiexec to unload DLLRegisterServer.
Upon triage, review parent process and capture any artifacts for further review.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where `process_msiexec`
Processes.process IN ("*/z*", "*-z*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process
IN ("*/z*", "*-z*") by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_msiexec_unregister_dllregisterserver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: This analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. Filter as needed.
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: This analytic will need to be tuned for your environment based
on legitimate usage of msiexec.exe. Filter as needed.
references:
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
tags:
analytic_story:
- Windows System Binary Proxy Execution MSIExec
@@ -37,7 +42,8 @@ tags:
impact: 70
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to unregister a file.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to unregister a file.
mitre_attack_id:
- T1218.007
nist:
@@ -67,14 +73,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 35
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,19 +6,23 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies odbcconf.exe, Windows Open Database Connectivity utility, utilizing the action function of regsvr to load a DLL.
An example will look like - odbcconf.exe /A { REGSVR T1218-2.dll }.
During triage, review parent process, parallel procesess and file modifications.
description: The following analytic identifies odbcconf.exe, Windows Open Database
Connectivity utility, utilizing the action function of regsvr to load a DLL. An
example will look like - odbcconf.exe /A { REGSVR T1218-2.dll }. During triage,
review parent process, parallel procesess and file modifications.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe
Processes.process IN ("*/a *", "*-a*") Processes.process="*regsvr*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_odbcconf_load_dll_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present and filtering may need to occur based on legitimate application usage. Filter as needed.
Processes.process IN ("*/a *", "*-a*") Processes.process="*regsvr*" by Processes.dest
Processes.user Processes.parent_process_name Processes.process_name Processes.process
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_odbcconf_load_dll_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present and filtering may need to occur
based on legitimate application usage. Filter as needed.
references:
- https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html
- https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw
@@ -43,7 +47,8 @@ tags:
- T1218.008
nist:
- DE.CM
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to circumvent controls.
observable:
- name: user
type: User
@@ -69,14 +74,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 42
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,18 +6,24 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies the odbcconf.exe, Windows Open Database Connectivity utility, loading up a resource file. The file extension is arbitrary and may be named anything. The resource file itself may have different commands supported by Odbcconf to load up a DLL (REGSVR) on disk or additional commands.
During triage, review file modifications and parallel processes.
description: The following analytic identifies the odbcconf.exe, Windows Open Database
Connectivity utility, loading up a resource file. The file extension is arbitrary
and may be named anything. The resource file itself may have different commands
supported by Odbcconf to load up a DLL (REGSVR) on disk or additional commands.
During triage, review file modifications and parallel processes.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe
Processes.process IN ("*-f *","*/f *") Processes.process="*.rsp*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_odbcconf_load_response_file_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present and filtering may need to occur based on legitimate application usage. Filter as needed.
Processes.process IN ("*-f *","*/f *") Processes.process="*.rsp*" by Processes.dest
Processes.user Processes.parent_process_name Processes.process_name Processes.process
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_odbcconf_load_response_file_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present and filtering may need to occur
based on legitimate application usage. Filter as needed.
references:
- https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html
- https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw
@@ -42,7 +48,8 @@ tags:
- T1218.008
nist:
- DE.CM
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to circumvent controls.
observable:
- name: user
type: User
@@ -68,14 +75,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 42
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,24 +6,32 @@ author: Michael Haag, Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies a Microsoft Office product spawning the Windows msdt.exe process. MSDT is a Diagnostics Troubleshooting Wizard native to Windows. This behavior is related to a recently identified sample utilizing protocol handlers to evade preventative controls, including if macros are disabled in the document.
During triage, review file modifications for html. In addition, parallel processes including PowerShell and CertUtil.
description: The following analytic identifies a Microsoft Office product spawning
the Windows msdt.exe process. MSDT is a Diagnostics Troubleshooting Wizard native
to Windows. This behavior is related to a recently identified sample utilizing protocol
handlers to evade preventative controls, including if macros are disabled in the
document. During triage, review file modifications for html. In addition, parallel
processes including PowerShell and CertUtil.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
IN ("winword.exe","excel.exe","powerpnt.exe","outlook.exe","mspub.exe","visio.exe") Processes.process_name=msdt.exe
by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `windows_office_product_spawning_msdt_filter`'
how_to_implement: how To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
IN ("winword.exe","excel.exe","powerpnt.exe","outlook.exe","mspub.exe","visio.exe")
Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `windows_office_product_spawning_msdt_filter`'
how_to_implement: how To successfully implement this search you need to be ingesting
information on process that include the name of the process responsible for the
changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
In addition, confirm the latest CIM App 4.20 or higher is installed and the latest
TA for the endpoint product.
known_false_positives: False positives should be limited, however filter as needed.
references:
- https://isc.sans.edu/diary/rss/28694
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
- https://isc.sans.edu/diary/rss/28694
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
tags:
analytic_story:
- Spearphishing Attachments
@@ -44,8 +52,8 @@ tags:
impact: 100
kill_chain_phases:
- Exploitation
message: Office parent process $parent_process_name$ has spawned a child
process $process_name$ on host $dest$.
message: Office parent process $parent_process_name$ has spawned a child process
$process_name$ on host $dest$.
mitre_attack_id:
- T1566
- T1566.001
@@ -76,14 +84,16 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 100
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -76,3 +76,5 @@ tags:
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,20 +6,21 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic is to look for known processes killed by industroyer2 malware.
This technique was seen in the industroyer2 malware attack that tries to kill several processes
of windows host machines related to the energy facility network. This anomaly might be a good
indicator to check which process kill these processes or why the process was killed.
search: '`sysmon` EventCode=5 process_name IN ("PServiceControl.exe", "PService_PPD.exe")
| stats min(_time) as firstTime max(_time) as lastTime count by process_name process process_path process_guid process_id EventCode dest user_id
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `windows_processes_killed_by_industroyer2_malware_filter`'
description: The following analytic is to look for known processes killed by industroyer2
malware. This technique was seen in the industroyer2 malware attack that tries to
kill several processes of windows host machines related to the energy facility network.
This anomaly might be a good indicator to check which process kill these processes
or why the process was killed.
search: '`sysmon` EventCode=5 process_name IN ("PServiceControl.exe", "PService_PPD.exe")
| stats min(_time) as firstTime max(_time) as lastTime count by process_name process
process_path process_guid process_id EventCode dest user_id | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `windows_processes_killed_by_industroyer2_malware_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also
required.
known_false_positives: False positives are possible if legitimate applications are
allowed to terminate this process during testing or updates. Filter as needed based on paths that
are used legitimately.
allowed to terminate this process during testing or updates. Filter as needed based
on paths that are used legitimately.
references:
- https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
tags:
@@ -69,3 +70,5 @@ tags:
- Processes.process_guid
risk_score: 36
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -79,3 +79,5 @@ tags:
risk_score: 80
security_domain: endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,18 +6,27 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies a process attempting to delete a scheduled task SD (Security Descriptor) from within the registry path of that task.
This may occur from a non-standard process running and may not come from reg.exe. This particular behavior will remove the actual Task Name from the Task Scheduler GUI and from the command-line query - schtasks.exe /query.
In addition, in order to perform this action, the user context will need to be SYSTEM.
description: The following analytic identifies a process attempting to delete a scheduled
task SD (Security Descriptor) from within the registry path of that task. This may
occur from a non-standard process running and may not come from reg.exe. This particular
behavior will remove the actual Task Name from the Task Scheduler GUI and from the
command-line query - schtasks.exe /query. In addition, in order to perform this
action, the user context will need to be SYSTEM.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
where Registry.registry_path IN ("*\\Schedule\\TaskCache\\Tree\\*") Registry.user="SYSTEM" Registry.registry_value_name="SD" (Registry.action=Deleted OR Registry.action=modified)
by _time Registry.dest Registry.process_guid Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.registry_value_data Registry.status Registry.action
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_registry_delete_task_sd_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives should be limited as the activity is not common to delete ONLY the SD from the registry. Filter as needed. Update the analytic Modified or Deleted values based on product that is in the datamodel.
where Registry.registry_path IN ("*\\Schedule\\TaskCache\\Tree\\*") Registry.user="SYSTEM"
Registry.registry_value_name="SD" (Registry.action=Deleted OR Registry.action=modified)
by _time Registry.dest Registry.process_guid Registry.user Registry.registry_path
Registry.registry_value_name Registry.registry_key_name Registry.registry_value_data
Registry.status Registry.action | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_registry_delete_task_sd_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited as the activity is not common
to delete ONLY the SD from the registry. Filter as needed. Update the analytic Modified
or Deleted values based on product that is in the datamodel.
references:
- https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/
- https://gist.github.com/MHaggis/5f7fd6745915166fc6da863d685e2728
@@ -45,7 +54,7 @@ tags:
- T1562
nist:
- DE.CM
message: A scheduled task security descriptor was deleted from the registry on $dest$.
message: A scheduled task security descriptor was deleted from the registry on $dest$.
observable:
- name: dest
type: Endpoint
@@ -61,10 +70,12 @@ tags:
- Registry.registry_key_name
- Registry.registry_value_name
- Registry.dest
- Processes.process_id
- Processes.process_name
- Processes.process_id
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.process_guid
- Processes.process_guid
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -76,3 +76,5 @@ tags:
risk_score: 80
security_domain: endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,23 +6,25 @@ author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies RDPWInst.exe tool, which is a RDP wrapper library tool designed to enable remote
desktop host support and concurrent RDP session on reduced functionality system. Unfortunately, this open project was abused by adversaries
to enable RDP connection to the targeted host for remote access and potentially be for lateral movement.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name="RDPWInst.exe" OR Processes.original_file_name="RDPWInst.exe")
AND Processes.process IN ("* -i*", "* -s*", "* -o*", "* -w*", "* -r*")
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_remote_service_rdpwinst_tool_execution_filter`'
description: The following analytic identifies RDPWInst.exe tool, which is a RDP wrapper
library tool designed to enable remote desktop host support and concurrent RDP session
on reduced functionality system. Unfortunately, this open project was abused by
adversaries to enable RDP connection to the targeted host for remote access and
potentially be for lateral movement.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name="RDPWInst.exe" OR Processes.original_file_name="RDPWInst.exe")
AND Processes.process IN ("* -i*", "* -s*", "* -o*", "* -w*", "* -r*") by Processes.dest
Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_remote_service_rdpwinst_tool_execution_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: This tool was designed for home usage and not commonly seen in production environment. Filter as needed.
known_false_positives: This tool was designed for home usage and not commonly seen
in production environment. Filter as needed.
references:
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
tags:
@@ -71,4 +73,6 @@ tags:
- Processes.process_path
- Processes.parent_process_id
risk_score: 81
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -7,25 +7,27 @@ type: Anomaly
datamodel:
- Endpoint
description: The following analytic is to identify a modification in the Windows firewall
to enable remote desktop protocol on a targeted machine. This technique was seen in several adversaries, malware or red teamer
to remotely access the compromised or targeted host by allowing this protocol in firewall. Even this protocol might be allowed in some
production environment, This TTP behavior is a good pivot to check who and why the user want to enable this feature through firewall which is also common traits
of attack to start lateral movement.
to enable remote desktop protocol on a targeted machine. This technique was seen
in several adversaries, malware or red teamer to remotely access the compromised
or targeted host by allowing this protocol in firewall. Even this protocol might
be allowed in some production environment, This TTP behavior is a good pivot to
check who and why the user want to enable this feature through firewall which is
also common traits of attack to start lateral movement.
search: '| tstats `security_content_summariesonly` values(Processes.process) as cmdline
values(Processes.parent_process_name) as parent_process values(Processes.process_name)
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = "netsh.exe" OR Processes.original_file_name= "netsh.exe") AND Processes.process = "*firewall*" AND Processes.process = "*add*" AND Processes.process = "*protocol=TCP*"
AND Processes.process = "*localport=3389*" AND Processes.process = "*action=allow*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name
where (Processes.process_name = "netsh.exe" OR Processes.original_file_name= "netsh.exe")
AND Processes.process = "*firewall*" AND Processes.process = "*add*" AND Processes.process
= "*protocol=TCP*" AND Processes.process = "*localport=3389*" AND Processes.process
= "*action=allow*" by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_remote_services_allow_rdp_in_firewall_filter`'
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_remote_services_allow_rdp_in_firewall_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records process activity from your hosts to populate the endpoint data model
in the processes node. If you are using Sysmon, you must have at least version 6.0.4
of the Sysmon TA.
known_false_positives: administrators may enable or disable this feature that may cause some false positive.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
tags:
@@ -72,3 +74,5 @@ tags:
- Processes.user
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -73,3 +73,5 @@ tags:
risk_score: 48
security_domain: endpoint
asset_type: Endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -4,7 +4,7 @@ version: 1
date: '2020-11-06'
author: Rod Soto, Jose Hernandez, Splunk
type: TTP
datamodel:
datamodel:
- Endpoint
description: The search looks for a Windows Security Account Manager (SAM) was stopped
via command-line. This is consistent with Ryuk infections across a fleet of endpoints.
@@ -68,3 +68,5 @@ tags:
- Processes.user
risk_score: 70
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,17 +6,22 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifes a new kernel driver being added to Windows using sc.exe.
Adding a Kernel driver is not common day to day and should be investigated to further understand the source.
description: The following analytic identifes a new kernel driver being added to Windows
using sc.exe. Adding a Kernel driver is not common day to day and should be investigated
to further understand the source.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sc.exe
Processes.process="*kernel*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_service_create_kernel_mode_driver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present based on common applications adding new drivers, however, filter as needed.
Processes.process="*kernel*" by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_service_create_kernel_mode_driver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present based on common applications
adding new drivers, however, filter as needed.
references:
- https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/
tags:
@@ -36,7 +41,8 @@ tags:
impact: 60
kill_chain_phases:
- Installation
message: Service control, $process_name$, loaded a new kernel mode driver on $dest$ by $user$.
message: Service control, $process_name$, loaded a new kernel mode driver on $dest$
by $user$.
mitre_attack_id:
- T1543.003
- T1543
@@ -61,11 +67,13 @@ tags:
- Processes.dest
- Processes.user
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 48
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -11,13 +11,13 @@ description: The following analytic identifies Windows Service Control, `sc.exe`
instances of service enumeration of attempts to stop a service and then delete it.
Adversaries utilize this technique to terminate security services or other related
services to continue there objective and evade detections.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = sc.exe OR Processes.original_file_name = sc.exe) Processes.process="* delete *" by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_service_stop_by_deletion_filter`'
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = sc.exe OR Processes.original_file_name = sc.exe)
Processes.process="* delete *" by Processes.dest Processes.user Processes.parent_process
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_service_stop_by_deletion_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
@@ -73,3 +73,5 @@ tags:
- Processes.user
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,22 +6,26 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies Windows commandlined to logoff a windows host machine.
This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact,
interrupt access, aid destruction of the system like wiping disk or inhibit system recovery.
This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
description: The following analytic identifies Windows commandlined to logoff a windows
host machine. This technique was seen in several APT, RAT like dcrat and other commodity
malware to shutdown the machine to add more impact, interrupt access, aid destruction
of the system like wiping disk or inhibit system recovery. This TTP is a good pivot
to check why application trigger this commandline which is not so common way to
logoff a machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe)
Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_system_logoff_commandline_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: Administrator may execute this commandline to trigger shutdown, logoff or restart the host machine.
known_false_positives: Administrator may execute this commandline to trigger shutdown,
logoff or restart the host machine.
references:
- https://attack.mitre.org/techniques/T1529/
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
@@ -71,3 +75,5 @@ tags:
- Processes.parent_process_id
risk_score: 56
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,23 +6,27 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies Windows commandlined to reboot a windows host machine.
This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact,
interrupt access, aid destruction of the system like wiping disk or inhibit system recovery.
This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine.
Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
description: The following analytic identifies Windows commandlined to reboot a windows
host machine. This technique was seen in several APT, RAT like dcrat and other commodity
malware to shutdown the machine to add more impact, interrupt access, aid destruction
of the system like wiping disk or inhibit system recovery. This TTP is a good pivot
to check why application trigger this commandline which is not so common way to
reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen
in some automation script like ansible to reboot the machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe)
Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_system_reboot_commandline_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: Administrator may execute this commandline to trigger shutdown or restart the host machine.
known_false_positives: Administrator may execute this commandline to trigger shutdown
or restart the host machine.
references:
- https://attack.mitre.org/techniques/T1529/
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
@@ -72,3 +76,5 @@ tags:
- Processes.parent_process_id
risk_score: 30
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,22 +6,26 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies Windows commandlined to shutdown a windows host machine.
This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact,
interrupt access, aid destruction of the system like wiping disk or inhibit system recovery.
This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
description: The following analytic identifies Windows commandlined to shutdown a
windows host machine. This technique was seen in several APT, RAT like dcrat and
other commodity malware to shutdown the machine to add more impact, interrupt access,
aid destruction of the system like wiping disk or inhibit system recovery. This
TTP is a good pivot to check why application trigger this commandline which is not
so common way to shutdown a machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe)
Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*"
by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_system_shutdown_commandline_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: Administrator may execute this commandline to trigger shutdown or restart the host machine.
known_false_positives: Administrator may execute this commandline to trigger shutdown
or restart the host machine.
references:
- https://attack.mitre.org/techniques/T1529/
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
@@ -71,3 +75,5 @@ tags:
- Processes.parent_process_id
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,19 +6,19 @@ author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies DCRat delay time tactics using w32tm.
This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like
c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who
execute this command that may lead to DCRat attack.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process= "* /computer:localhost *"
Processes.process= "* /period:*" Processes.process= "* /dataonly *" Processes.process= "* /samples:*"
by Processes.parent_process Processes.process_name Processes.original_file_name Processes.process
Processes.process_id Processes.parent_process_id Processes.dest Processes.user
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_system_time_discovery_w32tm_delay_filter`'
description: The following analytic identifies DCRat delay time tactics using w32tm.
This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe
application to delay the execution of its payload like c2 communication , beaconing
and execution. This anomaly detection may help the analyst to check other possible
event like the process who execute this command that may lead to DCRat attack.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process=
"* /computer:localhost *" Processes.process= "* /period:*" Processes.process= "*
/dataonly *" Processes.process= "* /samples:*" by Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_system_time_discovery_w32tm_delay_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
@@ -45,7 +45,8 @@ tags:
impact: 60
kill_chain_phases:
- Reconnaissance
message: Process name w32tm.exe is using suspcicious command line arguments $process$ on host $dest$.
message: Process name w32tm.exe is using suspcicious command line arguments $process$
on host $dest$.
mitre_attack_id:
- T1124
nist:
@@ -74,3 +75,5 @@ tags:
- Processes.parent_process_id
risk_score: 36
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -6,23 +6,25 @@ author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies net.exe updating user account policies for password requirement with non-expiring password.
This technique was seen in several adversaries and malware like Azorult to maintain the foothold (persistence), gaining privilege escalation, defense evasion and
possible for lateral movement for specific users or created user account on the targeted host. This TTP detections is a good pivot to see further what other events that users
executes on the machines.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where `process_net`
AND Processes.process="* accounts *" AND Processes.process="* /maxpwage:unlimited"
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
description: The following analytic identifies net.exe updating user account policies
for password requirement with non-expiring password. This technique was seen in
several adversaries and malware like Azorult to maintain the foothold (persistence),
gaining privilege escalation, defense evasion and possible for lateral movement
for specific users or created user account on the targeted host. This TTP detections
is a good pivot to see further what other events that users executes on the machines.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where `process_net` AND Processes.process="* accounts *" AND Processes.process="*
/maxpwage:unlimited" by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_valid_account_with_never_expires_password_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: This behavior is not commonly seen in production environment and not advisable, filter as needed.
known_false_positives: This behavior is not commonly seen in production environment
and not advisable, filter as needed.
references:
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
- https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/net-commands-on-operating-systems
@@ -73,4 +75,6 @@ tags:
- Processes.process_path
- Processes.parent_process_id
risk_score: 100
security_domain: endpoint
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
@@ -87,3 +87,5 @@ tags:
- user
risk_score: 15
security_domain: threat
supported_tas:
- Splunk_TA_nginx
@@ -6,18 +6,19 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Web
description: The following analytic is static indicators related to CVE-2022-22963, Spring4Shell. The 3 indicators provide an amount of fidelity that source IP is attemping to exploit a web shell on the destination.
The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity.
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET")
Web.url IN ("*tomcatwar.jsp*","*poc.jsp*","*shell.jsp*")
by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest
sourcetype
| `drop_dm_object_name("Web")`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `spring4shell_payload_url_request_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel.
known_false_positives: The jsp file names are static names used in current proof of concept code. =
description: The following analytic is static indicators related to CVE-2022-22963,
Spring4Shell. The 3 indicators provide an amount of fidelity that source IP is attemping
to exploit a web shell on the destination. The filename and cmd are arbitrary in
this exploitation. Java will write a JSP to disk and a process will spawn from Java
based on the cmd passed. This is indicative of typical web shell activity.
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url
IN ("*tomcatwar.jsp*","*poc.jsp*","*shell.jsp*") by Web.http_user_agent Web.http_method,
Web.url,Web.url_length Web.src, Web.dest sourcetype | `drop_dm_object_name("Web")`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `spring4shell_payload_url_request_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on Web traffic that include fields relavent for traffic into the `Web` datamodel.
known_false_positives: The jsp file names are static names used in current proof of
concept code. =
references:
- https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/
- https://github.com/TheGejr/SpringShell
@@ -70,3 +71,5 @@ tags:
- Web.http_user_agent
risk_score: 36
security_domain: network
supported_tas:
- Splunk_TA_nginx
+18 -14
View File
@@ -6,18 +6,19 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Web
description: The following analytic identifies the common URL requests used by a recent CVE - CVE-2022-22965, or Spring4Shell, to access a webshell on the remote webserver.
The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity.
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET")
Web.url IN ("*.jsp?cmd=*","*j&cmd=*")
by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest
sourcetype
| `drop_dm_object_name("Web")`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `web_jsp_request_via_url_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel.
known_false_positives: False positives may be present with legitimate applications. Attempt to filter by dest IP or use Asset groups to restrict to servers.
description: The following analytic identifies the common URL requests used by a recent
CVE - CVE-2022-22965, or Spring4Shell, to access a webshell on the remote webserver.
The filename and cmd are arbitrary in this exploitation. Java will write a JSP to
disk and a process will spawn from Java based on the cmd passed. This is indicative
of typical web shell activity.
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url
IN ("*.jsp?cmd=*","*j&cmd=*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length
Web.src, Web.dest sourcetype | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `web_jsp_request_via_url_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on Web traffic that include fields relavent for traffic into the `Web` datamodel.
known_false_positives: False positives may be present with legitimate applications.
Attempt to filter by dest IP or use Asset groups to restrict to servers.
references:
- https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/
- https://github.com/TheGejr/SpringShell
@@ -40,7 +41,8 @@ tags:
impact: 90
kill_chain_phases:
- Exploitation
message: A suspicious URL has been requested against $dest$ by $src$, related to web shell activity.
message: A suspicious URL has been requested against $dest$ by $src$, related to
web shell activity.
mitre_attack_id:
- T1505.003
- T1505
@@ -69,4 +71,6 @@ tags:
- Web.dest
- Web.http_user_agent
risk_score: 72
security_domain: network
security_domain: network
supported_tas:
- Splunk_TA_nginx
@@ -1,317 +1,393 @@
detection_name,cim_version,supported_tas,tas_with_cim_mapping
abnormally_high_number_of_cloud_security_group_api_calls,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
cloud_api_calls_from_previously_unseen_user_roles,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, splunk_ta_o365, Splunk_TA_box, Splunk_TA_infoblox, Splunk_TA_salesforce"
cloud_compute_instance_created_in_previously_unused_region,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
cloud_provisioning_from_previously_unseen_country,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
cloud_compute_instance_created_with_previously_unseen_instance_type,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
cloud_compute_instance_created_by_previously_unseen_user,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
cloud_provisioning_from_previously_unseen_region,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
abnormally_high_number_of_cloud_infrastructure_api_calls,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
cloud_compute_instance_created_with_previously_unseen_image,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
cloud_provisioning_from_previously_unseen_city,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
cloud_provisioning_from_previously_unseen_ip_address,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce"
cloud_instance_modified_with_previously_unseen_user,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce"
linux_setuid_using_chmod_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
disabling_folderoptions_windows_feature,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
anomalous_usage_of_7zip,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
enable_rdp_in_other_port_number,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
excessive_number_of_taskhost_processes,5.0.0,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
xsl_script_execution_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
rundll32_control_rundll_world_writable_directory,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_schedule_task,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
serviceprincipalnames_discovery_with_setspn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
allow_operation_with_consent_admin,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
windows_service_initiation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
spoolsv_writing_a_dll,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
dsquery_domain_discovery,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
linux_possible_access_or_modification_of_sshd_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
secretdumps_offline_ntds_dumping_tool,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
attacker_tools_on_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows"
domain_account_discovery_with_net_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
certutil_exe_certificate_extraction,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_html_help_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
prevent_automatic_repair_mode_using_bcdedit,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_possible_access_to_sudoers_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
get_domainpolicy_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
excessive_number_of_distinct_processes_created_in_windows_temp_folder,5.0.0,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
disable_registry_tool,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
powershell_disable_security_monitoring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
svchost_exe_lolbas_execution_process_spawn,5.0.0,,Splunk_TA_microsoft_sysmon
disable_defender_spynet_reporting,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
certutil_download_with_verifyctl_and_split_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_nirsoft_advancedrun,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
cmd_echo_pipe___escalation,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_number_of_service_control_start_as_disabled,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
windows_installutil_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_use_of_cmd_exe_to_launch_script_interpreters,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
suspicious_icedid_rundll32_cmdline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_service_stop_attempt,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_copy_on_system32,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
credential_dumping_via_symlink_to_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_searchprotocolhost_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_usage_of_net_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
permission_modification_using_takeown_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_at_application_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
reg_exe_manipulating_windows_services_registry_keys,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
logon_script_event_trigger_execution,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_possible_ssh_key_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
dump_lsass_via_procdump,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
getwmiobject_ds_computer_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
sdclt_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
hide_user_account_from_sign_in_screen,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
deleting_of_net_users,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
revil_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_psexec_with_accepteula_flag,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remote_process_instantiation_via_dcom_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
auto_admin_logon_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_doas_tool_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
modify_acl_permission_to_files_or_folder,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
getdomaingroup_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_amsi_through_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
wermgr_process_spawned_cmd_or_powershell_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_azurehound_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_product_spawning_rundll32_with_no_dll,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_exchange_web_shell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
time_provider_persistence_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
system_processes_run_from_unexpected_locations,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
scheduled_task_initiation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
sc_exe_manipulating_windows_services,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
disable_defender_submit_samples_consent_feature,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
ryuk_wake_on_lan_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
suspicious_msbuild_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_possible_access_to_credential_files,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
suspicious_wevtutil_usage,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
excessive_usage_of_cacls_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
disabling_task_manager,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
office_document_spawned_child_process_to_download,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
processes_launching_netsh,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_possible_append_command_to_at_allow_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
single_letter_process_on_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
check_elevated_cmd_using_whoami,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
short_lived_windows_accounts,5.0.0,,"Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_cyberark"
possible_lateral_movement_powershell_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
schtasks_scheduling_job_on_remote_system,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
executables_or_script_creation_in_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
active_setup_registry_autostart,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
suspicious_rundll32_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
winword_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_regsvr32_register_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_install_kernel_module_using_modprobe_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
scheduled_task_creation_on_remote_endpoint_using_at,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_possible_append_command_to_profile_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
nishang_powershelltcponeline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_mshta_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_sudoers_tmp_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_service_restarted,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
disabling_defender_services,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
getwmiobject_ds_group_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
firewall_allowed_program_enable,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
office_application_spawn_regsvr32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_rundll32_inline_hta_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_gpupdate_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
extraction_of_registry_hives,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
powershell_start_bitstransfer,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_mshta_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_rundll32_application_control_bypass___setupapi,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
recursive_delete_of_directory_in_batch_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
get_aduserresultantpasswordpolicy_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
windows_dotnet_binary_in_non_standard_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
net_profiler_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disable_etw_through_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
remote_process_instantiation_via_winrm_and_winrs,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_product_spawning_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
execution_of_file_with_multiple_extensions,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows"
remote_process_instantiation_via_winrm_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_process_file_path,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
any_powershell_downloadstring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_change_file_owner_to_root,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
process_creating_lnk_file_in_suspicious_location,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
wbadmin_delete_system_backups,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
linux_pkexec_privilege_escalation,5.0.0,,Splunk_TA_microsoft_sysmon
disabling_controlpanel,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
attempt_to_stop_security_service,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excel_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
allow_inbound_traffic_by_firewall_rule_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
getdomaincomputer_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
malicious_powershell_process___execution_policy_bypass,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_defender_enhanced_notification,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
fodhelper_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_regsvr32_application_control_bypass,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_curl_download_to_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remcos_client_registry_install_entry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_microsoft_workflow_compiler_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
bcdedit_failure_recovery_modification,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
linux_service_file_created_in_systemd_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
slui_runas_elevated,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
batch_file_write_to_system32,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_dism_remove_defender,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_usage_of_taskkill,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
nltest_domain_trust_discovery,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
fsutil_zeroing_file,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
office_application_spawn_rundll32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
add_or_set_windows_defender_exclusion,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
bitsadmin_download_file,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
print_processor_registry_autostart,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_path_interception_by_creation_of_program_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
cmdline_tool_not_executed_in_cmd_shell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_mshta_inline_hta_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_rundll32_startw,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
script_execution_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
slui_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
scheduled_task_deleted_or_created_via_cmd,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
allow_network_discovery_in_firewall,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_file_created_in_kernel_driver_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disable_logs_using_wevtutil,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
revil_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_sharphound_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
wmiprsve_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_file_creation_in_profile_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
services_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
regsvr32_with_known_silent_switch_cmdline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_installutil_uninstall_option,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
deleting_shadow_copies,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
winhlp32_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disabling_firewall_with_netsh,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
elevated_group_discovery_with_net,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_setuid_using_setcap_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
linux_preload_hijack_library_calls,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
windows_installutil_in_non_standard_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
get_foresttrust_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_defender_exclusion_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_adfind_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disabling_cmd_application,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
msmpeng_application_dll_side_loading,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
account_discovery_with_net_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_insert_kernel_module_using_insmod_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
certutil_download_with_urlcache_and_split_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_msbuild_rename,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_mshta_child_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
set_default_powershell_execution_policy_to_unrestricted_or_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
uninstall_app_using_msiexec,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
execute_javascript_with_jscript_com_clsid,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
create_local_admin_accounts_using_net_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_uac_remote_restriction,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_doas_conf_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
creation_of_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_file_creation_in_init_boot_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
windows_disableantispyware_reg,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disable_defender_mpengine_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
getwmiobject_ds_user_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disable_windows_app_hotkeys,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
dns_exfiltration_using_nslookup_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
clear_unallocated_sector_using_cipher_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_java_spawning_shell,5.0.0,,Splunk_TA_microsoft_sysmon
disable_defender_blockatfirstseen_feature,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remote_process_instantiation_via_wmi_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regsvcs_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
get_domaintrust_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_installutil_credential_theft,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
elevated_group_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
registry_keys_used_for_persistence,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_rundll32_application_control_bypass___syssetup,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
ping_sleep_batch_command,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_processes_used_for_system_network_configuration_discovery,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
clop_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_product_spawning_certutil,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
regsvr32_silent_and_install_param_dll_loading,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
msbuild_suspicious_spawned_by_script_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
hiding_files_and_directories_with_attrib_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows"
office_product_spawn_cmd_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
wsreset_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
certutil_with_decode_argument,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
allow_file_and_printing_sharing_in_firewall,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
system_information_discovery_detection,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
malicious_powershell_process_with_obfuscation_techniques,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_add_files_in_known_crontab_directories,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
eventvwr_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
icacls_deny_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
usn_journal_deletion,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
remote_system_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_html_help_using_infotech_storage_handlers,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_security_logs_using_minint_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
sdelete_application_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
curl_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
icacls_grant_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
winword_spawning_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
credential_dumping_via_copy_command_from_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regasm_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
enable_wdigest_uselogoncredential_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
control_loading_from_world_writable_directory,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remote_process_instantiation_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_dllhost_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
spoolsv_spawning_rundll32,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
conti_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
attempted_credential_dump_from_registry_via_reg_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
jscript_execution_using_cscript_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
bcdedit_command_back_to_normal_mode_boot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
rundll32_shimcache_flush,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
screensaver_event_trigger_execution,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
office_product_spawning_bitsadmin,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
change_default_file_association,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
wscript_or_cscript_suspicious_child_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
domain_controller_discovery_with_nltest,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_windows_behavior_monitoring,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
windows_curl_upload_to_remote_destination,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
unified_messaging_service_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_html_help_spawn_child_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regsvcs_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
linux_service_started_or_enabled,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
java_class_file_download_by_java_user_agent,5.0.0,,"Splunk_TA_citrix-netscaler, Splunk_TA_nginx, Splunk_TA_microsoft-iis, Splunk_TA_websense-cg, Splunk_TA_squid, Splunk_TA_haproxy, Splunk_TA_mcafee-wg, Splunk_TA_cisco-wsa"
linux_at_allow_config_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disable_defender_antivirus_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_visudo_utility_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
schtasks_run_task_on_demand,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
schtasks_used_for_forcing_a_reboot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
windows_raccine_scheduled_task_deletion,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
mshta_spawning_rundll32_or_regsvr32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_attempt_to_disable_services,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
get_domainuser_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
suspicious_scheduled_task_from_public_directory,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
rundll32_with_no_command_line_arguments_with_network,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_service_creation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_nopasswd_entry_in_sudoers_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
attempt_to_add_certificate_to_untrusted_store,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
process_kill_base_on_file_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
wsmprovhost_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
domain_account_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disabling_norun_windows_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
suspicious_rundll32_plugininit,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
file_with_samsam_extension,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
silentcleanup_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
ntdsutil_export_ntds,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
disabling_systemrestore_in_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
vbscript_execution_using_wscript_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_spawning_control,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regasm_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
start_up_during_safe_mode_boot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
office_product_spawning_mshta,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
change_to_safe_mode_with_network_config,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
potentially_malicious_code_on_commandline,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_rundll32_application_control_bypass___advpack,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
services_escalate_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
wget_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
remote_wmi_command_attempt,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
create_or_delete_windows_shares_using_net_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
unload_sysmon_filter_driver,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
resize_shadowstorage_volume,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
wmic_xsl_execution_via_url,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_reg_exe_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
etw_registry_disabled,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
process_execution_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
samsam_test_file_write,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
impacket_lateral_movement_commandline_parameters,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
dump_lsass_via_comsvcs_dll,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
creation_of_shadow_copy_with_wmic_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
overwriting_accessibility_binaries,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_ossec, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
add_defaultuser_and_password_in_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
bits_job_persistence,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_rundll32_dllregisterserver,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
any_powershell_downloadfile,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
mmc_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
w3wp_spawning_shell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_sharphound_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
detect_rclone_command_line_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_msbuild_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disabling_net_user_account,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
shim_database_installation_with_suspicious_parameters,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
dns_query_length_with_high_standard_deviation,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_isc-bind, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox"
cloud_compute_instance_created_in_previously_unused_region,5.0.1,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
abnormally_high_number_of_cloud_security_group_api_calls,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
abnormally_high_number_of_cloud_infrastructure_api_calls,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
cloud_provisioning_from_previously_unseen_region,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
cloud_provisioning_from_previously_unseen_city,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
cloud_provisioning_from_previously_unseen_ip_address,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose"
cloud_instance_modified_with_previously_unseen_user,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose"
cloud_compute_instance_created_by_previously_unseen_user,5.0.1,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
cloud_api_calls_from_previously_unseen_user_roles,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
cloud_provisioning_from_previously_unseen_country,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
spring4shell_payload_url_request,5.0.1,Splunk_TA_nginx,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
log4shell_jndi_payload_injection_attempt,5.0.1,Splunk_TA_nginx,Splunk_TA_nginx
vmware_workspace_one_freemarker_server_side_template_injection,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
web_spring_cloud_function_functionrouter,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
web_jsp_request_via_url,5.0.1,Splunk_TA_nginx,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
print_processor_registry_autostart,5.0.1,,Splunk_TA_bit9-carbonblack
dns_query_length_with_high_standard_deviation,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_isc-bind, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox"
f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
windows_service_initiation_on_remote_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regsvcs_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
process_kill_base_on_file_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
schtasks_scheduling_job_on_remote_system,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
shim_database_installation_with_suspicious_parameters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
disabling_firewall_with_netsh,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_binary_proxy_execution_mavinject_dll_injection,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
domain_controller_discovery_with_nltest,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_rundll32_application_control_bypass___syssetup,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_command_and_scripting_interpreter_path_traversal_exec,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
slui_runas_elevated,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_hide_notification_features_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
silentcleanup_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
deleting_shadow_copies,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
clop_common_exec_parameter,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_remote_service_rdpwinst_tool_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
wsreset_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_nirsoft_advancedrun,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
resize_shadowstorage_volume,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
attempted_credential_dump_from_registry_via_reg_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_process_file_path,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
slui_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_modify_registry_disable_windows_security_center_notif,5.0.1,,Splunk_TA_bit9-carbonblack
registry_keys_for_creating_shim_databases,5.0.1,,Splunk_TA_bit9-carbonblack
wermgr_process_spawned_cmd_or_powershell_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_obfuscated_files_or_information_base64_decode,5.0.1,,Splunk_TA_microsoft_sysmon
windows_disableantispyware_reg,5.0.1,,Splunk_TA_bit9-carbonblack
disabling_norun_windows_app,5.0.1,,Splunk_TA_bit9-carbonblack
single_letter_process_on_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
batch_file_write_to_system32,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
disabling_folderoptions_windows_feature,5.0.1,,Splunk_TA_bit9-carbonblack
linux_system_network_discovery,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_curl_upload_to_remote_destination,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_disable_lock_workstation_feature_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
wsmprovhost_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
winword_spawning_cmd,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
malicious_powershell_process___execution_policy_bypass,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
vbscript_execution_using_wscript_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
ntdsutil_export_ntds,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_system_shutdown_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_mshta_url_in_command_line,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
jscript_execution_using_cscript_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_remote_services_allow_remote_assistance,5.0.1,,Splunk_TA_bit9-carbonblack
add_defaultuser_and_password_in_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_adfind_exe,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
fsutil_zeroing_file,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
detect_rclone_command_line_usage,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remote_process_instantiation_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_possible_append_command_to_profile_config_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_office_product_spawning_msdt,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
nishang_powershelltcponeline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_usage_of_net_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_sharphound_usage,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
dump_lsass_via_procdump,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
domain_account_discovery_with_net_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_disable_shutdown_button_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_modify_show_compress_color_and_info_tip_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
msbuild_suspicious_spawned_by_script_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_usage_of_taskkill,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_impair_defense_deny_security_software_with_applocker,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_raccine_scheduled_task_deletion,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_rundll32_startw,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_psexec_with_accepteula_flag,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
get_aduserresultantpasswordpolicy_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
allow_file_and_printing_sharing_in_firewall,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
eventvwr_uac_bypass,5.0.1,,Splunk_TA_bit9-carbonblack
regsvr32_silent_and_install_param_dll_loading,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_valid_account_with_never_expires_password,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regsvcs_with_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
change_to_safe_mode_with_network_config,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
control_loading_from_world_writable_directory,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_scheduled_task_from_public_directory,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
cmd_echo_pipe___escalation,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_possible_append_command_to_at_allow_config_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
winhlp32_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_doas_conf_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_modify_registry_disable_toast_notifications,5.0.1,,Splunk_TA_bit9-carbonblack
permission_modification_using_takeown_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
detect_rundll32_application_control_bypass___advpack,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
create_or_delete_windows_shares_using_net_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
anomalous_usage_of_7zip,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_install_kernel_module_using_modprobe_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_remote_assistance_spawning_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
registry_keys_used_for_privilege_escalation,5.0.1,,Splunk_TA_bit9-carbonblack
windows_command_shell_dcrat_forkbomb_payload,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
domain_account_discovery_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_change_file_owner_to_root,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
executables_or_script_creation_in_suspicious_path,5.0.1,,"Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
suspicious_copy_on_system32,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
certutil_download_with_urlcache_and_split_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_registry_modification_for_safe_mode_persistence,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
hiding_files_and_directories_with_attrib_exe,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
enable_rdp_in_other_port_number,5.0.1,,Splunk_TA_bit9-carbonblack
dsquery_domain_discovery,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
credential_dumping_via_copy_command_from_shadow_copy,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
get_foresttrust_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
malicious_powershell_process_with_obfuscation_techniques,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
creation_of_shadow_copy,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
any_powershell_downloadstring,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
bcdedit_command_back_to_normal_mode_boot,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_deleted_registry_by_a_non_critical_process_file_path,5.0.1,,Splunk_TA_bit9-carbonblack
detect_html_help_url_in_command_line,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_service_creation_using_registry_entry,5.0.1,,Splunk_TA_bit9-carbonblack
dump_lsass_via_comsvcs_dll,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_high_frequency_of_file_deletion_in_boot_folder,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_curl_download_to_suspicious_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
powershell_disable_security_monitoring,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
icacls_grant_command,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
nltest_domain_trust_discovery,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
disable_amsi_through_registry,5.0.1,,Splunk_TA_bit9-carbonblack
detect_mshta_inline_hta_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_rasautou_dll_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
mmc_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
recursive_delete_of_directory_in_batch_cmd,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
revil_registry_entry,5.0.1,,Splunk_TA_bit9-carbonblack
linux_file_created_in_kernel_driver_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_system_time_discovery_w32tm_delay,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
system_information_discovery_detection,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
uninstall_app_using_msiexec,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
detect_rundll32_application_control_bypass___setupapi,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
w3wp_spawning_shell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_registry_delete_task_sd,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
powershell_start_bitstransfer,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regasm_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
hide_user_account_from_sign_in_screen,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
get_domaintrust_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
samsam_test_file_write,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
prevent_automatic_repair_mode_using_bcdedit,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
detect_regsvr32_application_control_bypass,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
schtasks_used_for_forcing_a_reboot,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
linux_deletion_of_services,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
svchost_exe_lolbas_execution_process_spawn,5.0.1,,Splunk_TA_microsoft_sysmon
windows_installutil_uninstall_option,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
account_discovery_with_net_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disabling_systemrestore_in_registry,5.0.1,,Splunk_TA_bit9-carbonblack
linux_possible_ssh_key_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
linux_nopasswd_entry_in_sudoers_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
create_local_admin_accounts_using_net_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_processes_used_for_system_network_configuration_discovery,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
processes_launching_netsh,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
excessive_distinct_processes_from_windows_temp,5.0.1,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
wget_download_and_bash_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
process_creating_lnk_file_in_suspicious_location,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
bcdedit_failure_recovery_modification,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_remote_access_software_rms_registry,5.0.1,,Splunk_TA_bit9-carbonblack
services_escalate_exe,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
scheduled_task_deleted_or_created_via_cmd,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
wscript_or_cscript_suspicious_child_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_at_application_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_indirect_command_execution_via_forfiles,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_disable_logoff_button_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
sdclt_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
clear_unallocated_sector_using_cipher_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
usn_journal_deletion,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
certutil_with_decode_argument,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_service_restarted,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
credential_dumping_via_symlink_to_shadow_copy,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
conti_common_exec_parameter,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
fodhelper_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
disable_schedule_task,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_system_reboot_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_azurehound_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remote_wmi_command_attempt,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_file_creation_in_init_boot_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
active_setup_registry_autostart,5.0.1,,Splunk_TA_bit9-carbonblack
linux_possible_access_to_credential_files,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
disabling_controlpanel,5.0.1,,Splunk_TA_bit9-carbonblack
windows_impair_defense_delete_win_defender_profile_registry,5.0.1,,Splunk_TA_bit9-carbonblack
possible_lateral_movement_powershell_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
dns_exfiltration_using_nslookup_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_path_interception_by_creation_of_program_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_visudo_utility_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
elevated_group_discovery_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_regsvr32_register_suspicious_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_rundll32_plugininit,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
bits_job_persistence,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
sc_exe_manipulating_windows_services,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
shim_database_file_creation,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_ossec, Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
excessive_number_of_taskhost_processes,5.0.1,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
scheduled_task_initiation_on_remote_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
bitsadmin_download_file,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_product_spawning_rundll32_with_no_dll,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_registry_tool,5.0.1,,Splunk_TA_bit9-carbonblack
linux_decode_base64_to_shell,5.0.1,,Splunk_TA_microsoft_sysmon
curl_download_and_bash_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
elevated_group_discovery_with_net,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disabling_cmd_application,5.0.1,,Splunk_TA_bit9-carbonblack
linux_deletion_of_ssl_certificate,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
short_lived_windows_accounts,5.0.1,,"Splunk_TA_cyberark, Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose"
spoolsv_writing_a_dll,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
get_domainuser_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
ryuk_wake_on_lan_command,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
unified_messaging_service_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
getwmiobject_ds_user_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
office_application_spawn_regsvr32_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_etw_through_registry,5.0.1,,Splunk_TA_bit9-carbonblack
rundll32_with_no_command_line_arguments_with_network,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_product_spawning_mshta,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_number_of_service_control_start_as_disabled,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_odbcconf_load_response_file,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
certutil_download_with_verifyctl_and_split_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_deletion_of_cron_jobs,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
suspicious_msbuild_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
execution_of_file_with_multiple_extensions,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_impair_defenses_disable_win_defender_auto_logging,5.0.1,,Splunk_TA_bit9-carbonblack
linux_kernel_module_enumeration,5.0.1,,Splunk_TA_microsoft_sysmon
office_product_spawn_cmd_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_disable_memory_crash_dump,5.0.1,,Splunk_TA_bit9-carbonblack
serviceprincipalnames_discovery_with_setspn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_doas_tool_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
suspicious_rundll32_dllregisterserver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_microsoft_workflow_compiler_usage,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_usage_of_cacls_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
linux_iptables_firewall_modification,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
remote_process_instantiation_via_winrm_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
getdomaincomputer_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_icedid_rundll32_cmdline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_java_spawning_shell,5.0.1,,Splunk_TA_microsoft_sysmon
windows_schtasks_create_run_as_system,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
firewall_allowed_program_enable,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
suspicious_gpupdate_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_registry_certificate_added,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
suspicious_mshta_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
revil_common_exec_parameter,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
wmic_xsl_execution_via_url,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
potentially_malicious_code_on_commandline,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_ssh_remote_services_script_execute,5.0.1,,Splunk_TA_microsoft_sysmon
mimikatz_passtheticket_commandline_parameters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_modify_registry_regedit_silent_reg_import,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
monitor_registry_keys_for_print_monitors,5.0.1,,Splunk_TA_bit9-carbonblack
cmdline_tool_not_executed_in_cmd_shell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_dism_remove_defender,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_html_help_using_infotech_storage_handlers,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_html_help_spawn_child_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_rundll32_inline_hta_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
time_provider_persistence_registry,5.0.1,,Splunk_TA_bit9-carbonblack
attacker_tools_on_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_service_stop_by_deletion,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
excessive_service_stop_attempt,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
icacls_deny_command,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
linux_deleting_critical_directory_using_rm_command,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
disable_windows_behavior_monitoring,5.0.1,,Splunk_TA_bit9-carbonblack
script_execution_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
secretdumps_offline_ntds_dumping_tool,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
remote_process_instantiation_via_winrm_and_winrs,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_msbuild_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_mshta_child_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_clipboard_data_copy,5.0.1,,Splunk_TA_microsoft_sysmon
rubeus_command_line_parameters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
set_default_powershell_execution_policy_to_unrestricted_or_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
linux_disable_services,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
unload_sysmon_filter_driver,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
process_execution_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
disabling_task_manager,5.0.1,,Splunk_TA_bit9-carbonblack
certutil_exe_certificate_extraction,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_disable_windows_group_policy_features_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
file_with_samsam_extension,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
rundll32_control_rundll_world_writable_directory,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
getdomaingroup_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
change_default_file_association,5.0.1,,Splunk_TA_bit9-carbonblack
rundll32_lockworkstation,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
ping_sleep_batch_command,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disabling_remote_user_account_control,5.0.1,,Splunk_TA_bit9-carbonblack
linux_sudoers_tmp_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
overwriting_accessibility_binaries,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_ossec, Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
rundll_loading_dll_by_ordinal,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_possible_access_or_modification_of_sshd_config_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
system_processes_run_from_unexpected_locations,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
spoolsv_spawning_rundll32,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_security_account_manager_stopped,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
windows_process_with_namedpipe_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
wbadmin_delete_system_backups,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
xsl_script_execution_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_add_files_in_known_crontab_directories,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
extraction_of_registry_hives,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_rundll32_with_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_mof_event_triggered_execution_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
registry_keys_used_for_persistence,5.0.1,,Splunk_TA_bit9-carbonblack
windows_modify_registry_disable_win_defender_raw_write_notif,5.0.1,,Splunk_TA_bit9-carbonblack
scheduled_task_creation_on_remote_endpoint_using_at,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
excessive_attempt_to_disable_services,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_indirect_command_execution_via_pcalua,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
windows_dotnet_binary_in_non_standard_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_searchprotocolhost_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_msiexec_unregister_dllregisterserver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
attempt_to_stop_security_service,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_installutil_in_non_standard_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
java_class_file_download_by_java_user_agent,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
linux_deletion_of_init_daemon_script,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
getwmiobject_ds_computer_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_stop_services,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
net_profiler_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_msiexec_spawn_discovery_command,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_ssh_authorized_keys_modification,5.0.1,,Splunk_TA_microsoft_sysmon
windows_disable_change_password_through_registry,5.0.1,,Splunk_TA_bit9-carbonblack
windows_remote_services_rdp_enable,5.0.1,,Splunk_TA_bit9-carbonblack
linux_at_allow_config_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
excel_spawning_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
logon_script_event_trigger_execution,5.0.1,,Splunk_TA_bit9-carbonblack
windows_processes_killed_by_industroyer2_malware,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
impacket_lateral_movement_commandline_parameters,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_regasm_with_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_application_spawn_rundll32_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_installutil_url_in_command_line,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
allow_operation_with_consent_admin,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
linux_preload_hijack_library_calls,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_installutil_credential_theft,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_service_create_kernel_mode_driver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disabling_net_user_account,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_exchange_web_shell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
windows_system_logoff_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_msiexec_remote_download,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
detect_use_of_cmd_exe_to_launch_script_interpreters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
regsvr32_with_known_silent_switch_cmdline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_pkexec_privilege_escalation,5.0.1,,Splunk_TA_microsoft_sysmon
reg_exe_manipulating_windows_services_registry_keys,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
linux_insert_kernel_module_using_insmod_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
add_or_set_windows_defender_exclusion,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_linux_discovery_commands,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
office_product_spawning_wmic,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
disable_logs_using_wevtutil,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
deleting_of_net_users,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
sdelete_application_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
remote_process_instantiation_via_wmi_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
rundll32_shimcache_flush,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_writes_to_windows_recycle_bin,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
modify_acl_permission_to_files_or_folder,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_remote_services_allow_rdp_in_firewall,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
any_powershell_downloadfile,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
schtasks_run_task_on_demand,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
remote_system_discovery_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_reg_exe_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_msiexec_dllregisterserver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_possible_access_to_sudoers_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_modify_registry_disabling_wer_settings,5.0.1,,Splunk_TA_bit9-carbonblack
remote_process_instantiation_via_dcom_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
screensaver_event_trigger_execution,5.0.1,,Splunk_TA_bit9-carbonblack
get_domainpolicy_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
msmpeng_application_dll_side_loading,5.0.1,,"Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
services_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
auto_admin_logon_registry_entry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
ryuk_test_files_detected,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
check_elevated_cmd_using_whoami,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
creation_of_shadow_copy_with_wmic_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_shred_overwrite_command,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_file_without_extension_in_critical_folder,5.0.1,,Splunk_TA_bit9-carbonblack
linux_dd_file_overwrite,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
disable_windows_app_hotkeys,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
getwmiobject_ds_group_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
office_spawning_control,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
execute_javascript_with_jscript_com_clsid,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
mshta_spawning_rundll32_or_regsvr32_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
allow_network_discovery_in_firewall,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_dllhost_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_high_frequency_of_file_deletion_in_etc_folder,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
winword_spawning_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_modify_registry_disallow_windows_app,5.0.1,,Splunk_TA_bit9-carbonblack
detect_sharphound_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
wmiprsve_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
suspicious_wevtutil_usage,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_execute_arbitrary_commands_with_msdt,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_service_started_or_enabled,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
office_document_spawned_child_process_to_download,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
windows_odbcconf_load_dll,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
attempt_to_add_certificate_to_untrusted_store,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
linux_setuid_using_setcap_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
windows_modify_registry_suppress_win_defender_notif,5.0.1,,Splunk_TA_bit9-carbonblack
linux_setuid_using_chmod_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
office_product_spawning_certutil,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_file_creation_in_profile_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
windows_service_creation_on_remote_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_account_manipulation_of_ssh_config_and_keys,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
office_product_spawning_bitsadmin,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
linux_service_file_created_in_systemd_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
1 detection_name cim_version supported_tas tas_with_cim_mapping
2 abnormally_high_number_of_cloud_security_group_api_calls cloud_compute_instance_created_in_previously_unused_region 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce Splunk_TA_aws-kinesis-firehose
3 cloud_api_calls_from_previously_unseen_user_roles abnormally_high_number_of_cloud_security_group_api_calls 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, splunk_ta_o365, Splunk_TA_box, Splunk_TA_infoblox, Splunk_TA_salesforce Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox
4 cloud_compute_instance_created_in_previously_unused_region abnormally_high_number_of_cloud_infrastructure_api_calls 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_aws-kinesis-firehose Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox
5 cloud_provisioning_from_previously_unseen_country cloud_provisioning_from_previously_unseen_region 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox
6 cloud_compute_instance_created_with_previously_unseen_instance_type cloud_provisioning_from_previously_unseen_city 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_aws-kinesis-firehose Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox
7 cloud_compute_instance_created_by_previously_unseen_user cloud_provisioning_from_previously_unseen_ip_address 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_aws-kinesis-firehose Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose
8 cloud_provisioning_from_previously_unseen_region cloud_instance_modified_with_previously_unseen_user 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose
9 abnormally_high_number_of_cloud_infrastructure_api_calls cloud_compute_instance_created_by_previously_unseen_user 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce Splunk_TA_aws-kinesis-firehose
10 cloud_compute_instance_created_with_previously_unseen_image cloud_api_calls_from_previously_unseen_user_roles 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_aws-kinesis-firehose Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox
11 cloud_provisioning_from_previously_unseen_city cloud_provisioning_from_previously_unseen_country 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox
12 cloud_provisioning_from_previously_unseen_ip_address spring4shell_payload_url_request 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_nginx Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx
13 cloud_instance_modified_with_previously_unseen_user log4shell_jndi_payload_injection_attempt 5.0.0 5.0.1 Splunk_TA_aws-kinesis-firehose Splunk_TA_nginx Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce Splunk_TA_nginx
14 linux_setuid_using_chmod_utility vmware_workspace_one_freemarker_server_side_template_injection 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx
15 disabling_folderoptions_windows_feature web_spring_cloud_function_functionrouter 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx
16 anomalous_usage_of_7zip web_jsp_request_via_url 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nginx Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx
17 enable_rdp_in_other_port_number print_processor_registry_autostart 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
18 excessive_number_of_taskhost_processes dns_query_length_with_high_standard_deviation 5.0.0 5.0.1 Splunk_TA_windows Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_isc-bind, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox
19 xsl_script_execution_with_wmic f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx
20 rundll32_control_rundll_world_writable_directory windows_service_initiation_on_remote_endpoint 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
21 disable_schedule_task detect_regsvcs_spawning_a_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
22 serviceprincipalnames_discovery_with_setspn process_kill_base_on_file_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
23 allow_operation_with_consent_admin schtasks_scheduling_job_on_remote_system 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
24 windows_service_initiation_on_remote_endpoint shim_database_installation_with_suspicious_parameters 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
25 spoolsv_writing_a_dll disabling_firewall_with_netsh 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
26 dsquery_domain_discovery windows_binary_proxy_execution_mavinject_dll_injection 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
27 linux_possible_access_or_modification_of_sshd_config_file domain_controller_discovery_with_nltest 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
28 secretdumps_offline_ntds_dumping_tool detect_rundll32_application_control_bypass___syssetup 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
29 attacker_tools_on_endpoint windows_command_and_scripting_interpreter_path_traversal_exec 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows Splunk_TA_microsoft_sysmon
30 domain_account_discovery_with_net_app slui_runas_elevated 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
31 certutil_exe_certificate_extraction windows_hide_notification_features_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
32 detect_html_help_url_in_command_line silentcleanup_uac_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
33 prevent_automatic_repair_mode_using_bcdedit deleting_shadow_copies 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
34 linux_possible_access_to_sudoers_file clop_common_exec_parameter 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
35 get_domainpolicy_with_powershell windows_remote_service_rdpwinst_tool_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
36 excessive_number_of_distinct_processes_created_in_windows_temp_folder wsreset_uac_bypass 5.0.0 5.0.1 Splunk_TA_windows Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
37 disable_registry_tool windows_nirsoft_advancedrun 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
38 powershell_disable_security_monitoring resize_shadowstorage_volume 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
39 svchost_exe_lolbas_execution_process_spawn attempted_credential_dump_from_registry_via_reg_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
40 disable_defender_spynet_reporting suspicious_process_file_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
41 certutil_download_with_verifyctl_and_split_arguments slui_spawning_a_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
42 windows_nirsoft_advancedrun windows_modify_registry_disable_windows_security_center_notif 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
43 cmd_echo_pipe___escalation registry_keys_for_creating_shim_databases 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
44 excessive_number_of_service_control_start_as_disabled wermgr_process_spawned_cmd_or_powershell_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
45 windows_installutil_url_in_command_line linux_obfuscated_files_or_information_base64_decode 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
46 detect_use_of_cmd_exe_to_launch_script_interpreters windows_disableantispyware_reg 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
47 suspicious_icedid_rundll32_cmdline disabling_norun_windows_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
48 excessive_service_stop_attempt single_letter_process_on_endpoint 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR
49 suspicious_copy_on_system32 batch_file_write_to_system32 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
50 credential_dumping_via_symlink_to_shadow_copy disabling_folderoptions_windows_feature 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
51 suspicious_searchprotocolhost_no_command_line_arguments linux_system_network_discovery 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
52 excessive_usage_of_net_app windows_curl_upload_to_remote_destination 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
53 permission_modification_using_takeown_app windows_disable_lock_workstation_feature_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
54 linux_at_application_execution wsmprovhost_exe_lolbas_execution_process_spawn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
55 reg_exe_manipulating_windows_services_registry_keys winword_spawning_cmd 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
56 logon_script_event_trigger_execution malicious_powershell_process___execution_policy_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
57 linux_possible_ssh_key_file_creation vbscript_execution_using_wscript_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
58 dump_lsass_via_procdump ntdsutil_export_ntds 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
59 getwmiobject_ds_computer_with_powershell windows_system_shutdown_commandline 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
60 sdclt_uac_bypass detect_mshta_url_in_command_line 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
61 hide_user_account_from_sign_in_screen jscript_execution_using_cscript_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
62 deleting_of_net_users windows_remote_services_allow_remote_assistance 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
63 revil_registry_entry add_defaultuser_and_password_in_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
64 detect_psexec_with_accepteula_flag windows_adfind_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
65 remote_process_instantiation_via_dcom_and_powershell fsutil_zeroing_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
66 auto_admin_logon_registry_entry detect_rclone_command_line_usage 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
67 linux_doas_tool_execution remote_process_instantiation_via_wmi 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
68 modify_acl_permission_to_files_or_folder linux_possible_append_command_to_profile_config_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
69 getdomaingroup_with_powershell windows_office_product_spawning_msdt 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
70 disable_amsi_through_registry nishang_powershelltcponeline 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
71 wermgr_process_spawned_cmd_or_powershell_process excessive_usage_of_net_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
72 detect_azurehound_command_line_arguments detect_sharphound_usage 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
73 office_product_spawning_rundll32_with_no_dll dump_lsass_via_procdump 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
74 detect_exchange_web_shell domain_account_discovery_with_net_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
75 time_provider_persistence_registry windows_disable_shutdown_button_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
76 system_processes_run_from_unexpected_locations windows_modify_show_compress_color_and_info_tip_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
77 scheduled_task_initiation_on_remote_endpoint msbuild_suspicious_spawned_by_script_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
78 sc_exe_manipulating_windows_services excessive_usage_of_taskkill 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
79 disable_defender_submit_samples_consent_feature windows_impair_defense_deny_security_software_with_applocker 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
80 ryuk_wake_on_lan_command windows_raccine_scheduled_task_deletion 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
81 suspicious_msbuild_spawn suspicious_rundll32_startw 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
82 linux_possible_access_to_credential_files detect_psexec_with_accepteula_flag 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
83 suspicious_wevtutil_usage get_aduserresultantpasswordpolicy_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
84 excessive_usage_of_cacls_app allow_file_and_printing_sharing_in_firewall 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
85 disabling_task_manager eventvwr_uac_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
86 office_document_spawned_child_process_to_download regsvr32_silent_and_install_param_dll_loading 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
87 processes_launching_netsh windows_valid_account_with_never_expires_password 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
88 linux_possible_append_command_to_at_allow_config_file detect_regsvcs_with_no_command_line_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
89 single_letter_process_on_endpoint change_to_safe_mode_with_network_config 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
90 check_elevated_cmd_using_whoami control_loading_from_world_writable_directory 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
91 short_lived_windows_accounts suspicious_scheduled_task_from_public_directory 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_cyberark Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
92 possible_lateral_movement_powershell_spawn cmd_echo_pipe___escalation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
93 schtasks_scheduling_job_on_remote_system linux_possible_append_command_to_at_allow_config_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
94 executables_or_script_creation_in_suspicious_path winhlp32_spawning_a_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
95 active_setup_registry_autostart linux_doas_conf_file_creation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
96 suspicious_rundll32_with_no_command_line_arguments windows_modify_registry_disable_toast_notifications 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
97 winword_spawning_powershell permission_modification_using_takeown_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
98 suspicious_regsvr32_register_suspicious_path detect_rundll32_application_control_bypass___advpack 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
99 linux_install_kernel_module_using_modprobe_utility create_or_delete_windows_shares_using_net_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
100 scheduled_task_creation_on_remote_endpoint_using_at anomalous_usage_of_7zip 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
101 linux_possible_append_command_to_profile_config_file linux_install_kernel_module_using_modprobe_utility 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
102 nishang_powershelltcponeline windows_remote_assistance_spawning_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
103 detect_mshta_url_in_command_line registry_keys_used_for_privilege_escalation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
104 linux_sudoers_tmp_file_creation windows_command_shell_dcrat_forkbomb_payload 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
105 linux_service_restarted domain_account_discovery_with_wmic 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
106 disabling_defender_services linux_change_file_owner_to_root 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
107 getwmiobject_ds_group_with_powershell executables_or_script_creation_in_suspicious_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
108 firewall_allowed_program_enable suspicious_copy_on_system32 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
109 office_application_spawn_regsvr32_process certutil_download_with_urlcache_and_split_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
110 detect_rundll32_inline_hta_execution windows_registry_modification_for_safe_mode_persistence 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
111 suspicious_gpupdate_no_command_line_arguments hiding_files_and_directories_with_attrib_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
112 extraction_of_registry_hives enable_rdp_in_other_port_number 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
113 powershell_start_bitstransfer dsquery_domain_discovery 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
114 suspicious_mshta_spawn credential_dumping_via_copy_command_from_shadow_copy 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
115 detect_rundll32_application_control_bypass___setupapi get_foresttrust_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
116 recursive_delete_of_directory_in_batch_cmd malicious_powershell_process_with_obfuscation_techniques 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
117 get_aduserresultantpasswordpolicy_with_powershell creation_of_shadow_copy 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
118 windows_dotnet_binary_in_non_standard_path any_powershell_downloadstring 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
119 net_profiler_uac_bypass bcdedit_command_back_to_normal_mode_boot 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
120 disable_etw_through_registry windows_deleted_registry_by_a_non_critical_process_file_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
121 remote_process_instantiation_via_winrm_and_winrs detect_html_help_url_in_command_line 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
122 office_product_spawning_wmic windows_service_creation_using_registry_entry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
123 execution_of_file_with_multiple_extensions dump_lsass_via_comsvcs_dll 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows Splunk_TA_microsoft_sysmon
124 remote_process_instantiation_via_winrm_and_powershell linux_high_frequency_of_file_deletion_in_boot_folder 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
125 suspicious_process_file_path windows_curl_download_to_suspicious_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
126 any_powershell_downloadstring powershell_disable_security_monitoring 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
127 linux_change_file_owner_to_root icacls_grant_command 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
128 process_creating_lnk_file_in_suspicious_location nltest_domain_trust_discovery 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
129 wbadmin_delete_system_backups disable_amsi_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_bit9-carbonblack
130 linux_pkexec_privilege_escalation detect_mshta_inline_hta_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
131 disabling_controlpanel windows_rasautou_dll_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
132 attempt_to_stop_security_service mmc_exe_lolbas_execution_process_spawn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
133 excel_spawning_powershell recursive_delete_of_directory_in_batch_cmd 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
134 allow_inbound_traffic_by_firewall_rule_registry revil_registry_entry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
135 getdomaincomputer_with_powershell linux_file_created_in_kernel_driver_directory 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
136 malicious_powershell_process___execution_policy_bypass windows_system_time_discovery_w32tm_delay 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
137 disable_defender_enhanced_notification system_information_discovery_detection 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR
138 fodhelper_uac_bypass uninstall_app_using_msiexec 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
139 detect_regsvr32_application_control_bypass detect_rundll32_application_control_bypass___setupapi 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
140 windows_curl_download_to_suspicious_path w3wp_spawning_shell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
141 remcos_client_registry_install_entry windows_registry_delete_task_sd 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
142 suspicious_microsoft_workflow_compiler_usage powershell_start_bitstransfer 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
143 bcdedit_failure_recovery_modification detect_regasm_spawning_a_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
144 linux_service_file_created_in_systemd_directory hide_user_account_from_sign_in_screen 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
145 slui_runas_elevated get_domaintrust_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
146 batch_file_write_to_system32 samsam_test_file_write 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR
147 windows_dism_remove_defender prevent_automatic_repair_mode_using_bcdedit 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
148 excessive_usage_of_taskkill detect_regsvr32_application_control_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
149 nltest_domain_trust_discovery schtasks_used_for_forcing_a_reboot 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
150 fsutil_zeroing_file linux_deletion_of_services 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
151 office_application_spawn_rundll32_process svchost_exe_lolbas_execution_process_spawn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
152 add_or_set_windows_defender_exclusion windows_installutil_uninstall_option 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
153 bitsadmin_download_file account_discovery_with_net_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
154 print_processor_registry_autostart disabling_systemrestore_in_registry 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
155 detect_path_interception_by_creation_of_program_exe linux_possible_ssh_key_file_creation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
156 cmdline_tool_not_executed_in_cmd_shell linux_nopasswd_entry_in_sudoers_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
157 detect_mshta_inline_hta_execution create_local_admin_accounts_using_net_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
158 suspicious_rundll32_startw detect_processes_used_for_system_network_configuration_discovery 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
159 script_execution_via_wmi processes_launching_netsh 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
160 slui_spawning_a_process excessive_distinct_processes_from_windows_temp 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_windows Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR
161 scheduled_task_deleted_or_created_via_cmd wget_download_and_bash_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
162 allow_network_discovery_in_firewall process_creating_lnk_file_in_suspicious_location 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
163 linux_file_created_in_kernel_driver_directory bcdedit_failure_recovery_modification 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
164 disable_logs_using_wevtutil windows_remote_access_software_rms_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
165 revil_common_exec_parameter services_escalate_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
166 detect_sharphound_usage scheduled_task_deleted_or_created_via_cmd 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
167 wmiprsve_exe_lolbas_execution_process_spawn wscript_or_cscript_suspicious_child_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
168 linux_file_creation_in_profile_directory linux_at_application_execution 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
169 services_exe_lolbas_execution_process_spawn windows_indirect_command_execution_via_forfiles 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
170 regsvr32_with_known_silent_switch_cmdline windows_disable_logoff_button_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
171 windows_installutil_uninstall_option sdclt_uac_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
172 deleting_shadow_copies clear_unallocated_sector_using_cipher_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
173 winhlp32_spawning_a_process usn_journal_deletion 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
174 disabling_firewall_with_netsh certutil_with_decode_argument 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
175 elevated_group_discovery_with_net linux_service_restarted 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
176 linux_setuid_using_setcap_utility credential_dumping_via_symlink_to_shadow_copy 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
177 linux_preload_hijack_library_calls conti_common_exec_parameter 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
178 windows_installutil_in_non_standard_path fodhelper_uac_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
179 get_foresttrust_with_powershell disable_schedule_task 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
180 windows_defender_exclusion_registry_entry windows_system_reboot_commandline 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
181 windows_adfind_exe detect_azurehound_command_line_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
182 disabling_cmd_application remote_wmi_command_attempt 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
183 msmpeng_application_dll_side_loading linux_file_creation_in_init_boot_directory 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
184 account_discovery_with_net_app active_setup_registry_autostart 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
185 linux_insert_kernel_module_using_insmod_utility linux_possible_access_to_credential_files 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
186 certutil_download_with_urlcache_and_split_arguments disabling_controlpanel 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
187 suspicious_msbuild_rename windows_impair_defense_delete_win_defender_profile_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
188 suspicious_mshta_child_process possible_lateral_movement_powershell_spawn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
189 set_default_powershell_execution_policy_to_unrestricted_or_bypass dns_exfiltration_using_nslookup_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
190 uninstall_app_using_msiexec detect_path_interception_by_creation_of_program_exe 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
191 execute_javascript_with_jscript_com_clsid linux_visudo_utility_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
192 create_local_admin_accounts_using_net_exe elevated_group_discovery_with_wmic 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
193 disable_uac_remote_restriction suspicious_regsvr32_register_suspicious_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
194 linux_doas_conf_file_creation suspicious_rundll32_plugininit 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
195 creation_of_shadow_copy bits_job_persistence 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
196 linux_file_creation_in_init_boot_directory sc_exe_manipulating_windows_services 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
197 windows_disableantispyware_reg shim_database_file_creation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_ossec, Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
198 disable_defender_mpengine_registry excessive_number_of_taskhost_processes 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_windows Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
199 getwmiobject_ds_user_with_powershell scheduled_task_initiation_on_remote_endpoint 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
200 disable_windows_app_hotkeys bitsadmin_download_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
201 dns_exfiltration_using_nslookup_app office_product_spawning_rundll32_with_no_dll 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
202 clear_unallocated_sector_using_cipher_app disable_registry_tool 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
203 linux_java_spawning_shell linux_decode_base64_to_shell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon
204 disable_defender_blockatfirstseen_feature curl_download_and_bash_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
205 remote_process_instantiation_via_wmi_and_powershell elevated_group_discovery_with_net 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
206 detect_regsvcs_with_no_command_line_arguments disabling_cmd_application 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
207 get_domaintrust_with_powershell linux_deletion_of_ssl_certificate 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
208 windows_installutil_credential_theft short_lived_windows_accounts 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_cyberark, Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose
209 elevated_group_discovery_with_wmic spoolsv_writing_a_dll 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
210 registry_keys_used_for_persistence get_domainuser_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
211 detect_rundll32_application_control_bypass___syssetup ryuk_wake_on_lan_command 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
212 ping_sleep_batch_command unified_messaging_service_spawning_a_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
213 detect_processes_used_for_system_network_configuration_discovery getwmiobject_ds_user_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
214 clop_common_exec_parameter office_application_spawn_regsvr32_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
215 office_product_spawning_certutil disable_etw_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
216 regsvr32_silent_and_install_param_dll_loading rundll32_with_no_command_line_arguments_with_network 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
217 msbuild_suspicious_spawned_by_script_process office_product_spawning_mshta 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
218 hiding_files_and_directories_with_attrib_exe excessive_number_of_service_control_start_as_disabled 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
219 office_product_spawn_cmd_process windows_odbcconf_load_response_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
220 wsreset_uac_bypass certutil_download_with_verifyctl_and_split_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
221 certutil_with_decode_argument linux_deletion_of_cron_jobs 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
222 allow_file_and_printing_sharing_in_firewall suspicious_msbuild_spawn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
223 system_information_discovery_detection execution_of_file_with_multiple_extensions 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
224 malicious_powershell_process_with_obfuscation_techniques windows_impair_defenses_disable_win_defender_auto_logging 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
225 linux_add_files_in_known_crontab_directories linux_kernel_module_enumeration 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
226 eventvwr_uac_bypass office_product_spawn_cmd_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
227 icacls_deny_command windows_disable_memory_crash_dump 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_bit9-carbonblack
228 usn_journal_deletion serviceprincipalnames_discovery_with_setspn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
229 remote_system_discovery_with_wmic linux_doas_tool_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
230 detect_html_help_using_infotech_storage_handlers suspicious_rundll32_dllregisterserver 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
231 disable_security_logs_using_minint_registry suspicious_microsoft_workflow_compiler_usage 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
232 sdelete_application_execution excessive_usage_of_cacls_app 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
233 curl_download_and_bash_execution linux_iptables_firewall_modification 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
234 icacls_grant_command remote_process_instantiation_via_winrm_and_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
235 winword_spawning_cmd getdomaincomputer_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
236 credential_dumping_via_copy_command_from_shadow_copy suspicious_icedid_rundll32_cmdline 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
237 detect_regasm_with_no_command_line_arguments linux_java_spawning_shell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
238 enable_wdigest_uselogoncredential_registry windows_schtasks_create_run_as_system 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
239 control_loading_from_world_writable_directory firewall_allowed_program_enable 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
240 remote_process_instantiation_via_wmi suspicious_gpupdate_no_command_line_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
241 suspicious_dllhost_no_command_line_arguments windows_registry_certificate_added 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
242 spoolsv_spawning_rundll32 suspicious_mshta_spawn 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
243 conti_common_exec_parameter revil_common_exec_parameter 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
244 attempted_credential_dump_from_registry_via_reg_exe wmic_xsl_execution_via_url 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
245 jscript_execution_using_cscript_app potentially_malicious_code_on_commandline 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
246 bcdedit_command_back_to_normal_mode_boot linux_ssh_remote_services_script_execute 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
247 rundll32_shimcache_flush mimikatz_passtheticket_commandline_parameters 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
248 screensaver_event_trigger_execution windows_modify_registry_regedit_silent_reg_import 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
249 office_product_spawning_bitsadmin monitor_registry_keys_for_print_monitors 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
250 change_default_file_association cmdline_tool_not_executed_in_cmd_shell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
251 wscript_or_cscript_suspicious_child_process windows_dism_remove_defender 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
252 domain_controller_discovery_with_nltest detect_html_help_using_infotech_storage_handlers 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
253 disable_windows_behavior_monitoring detect_html_help_spawn_child_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
254 windows_curl_upload_to_remote_destination detect_rundll32_inline_hta_execution 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
255 unified_messaging_service_spawning_a_process time_provider_persistence_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
256 detect_html_help_spawn_child_process attacker_tools_on_endpoint 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
257 detect_regsvcs_spawning_a_process windows_service_stop_by_deletion 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
258 linux_service_started_or_enabled excessive_service_stop_attempt 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
259 java_class_file_download_by_java_user_agent icacls_deny_command 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_citrix-netscaler, Splunk_TA_nginx, Splunk_TA_microsoft-iis, Splunk_TA_websense-cg, Splunk_TA_squid, Splunk_TA_haproxy, Splunk_TA_mcafee-wg, Splunk_TA_cisco-wsa Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
260 linux_at_allow_config_file_creation linux_deleting_critical_directory_using_rm_command 5.0.0 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
261 disable_defender_antivirus_registry disable_windows_behavior_monitoring 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
262 linux_visudo_utility_execution script_execution_via_wmi 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR
263 schtasks_run_task_on_demand secretdumps_offline_ntds_dumping_tool 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
264 schtasks_used_for_forcing_a_reboot remote_process_instantiation_via_winrm_and_winrs 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
265 windows_raccine_scheduled_task_deletion suspicious_msbuild_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
266 mshta_spawning_rundll32_or_regsvr32_process suspicious_mshta_child_process 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
267 excessive_attempt_to_disable_services linux_clipboard_data_copy 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
268 get_domainuser_with_powershell rubeus_command_line_parameters 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
269 suspicious_scheduled_task_from_public_directory set_default_powershell_execution_policy_to_unrestricted_or_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
270 rundll32_with_no_command_line_arguments_with_network linux_disable_services 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
271 windows_service_creation_on_remote_endpoint unload_sysmon_filter_driver 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
272 linux_nopasswd_entry_in_sudoers_file process_execution_via_wmi 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
273 attempt_to_add_certificate_to_untrusted_store disabling_task_manager 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
274 process_kill_base_on_file_path certutil_exe_certificate_extraction 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
275 wsmprovhost_exe_lolbas_execution_process_spawn windows_disable_windows_group_policy_features_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
276 domain_account_discovery_with_wmic file_with_samsam_extension 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR
277 disabling_norun_windows_app rundll32_control_rundll_world_writable_directory 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
278 suspicious_rundll32_plugininit getdomaingroup_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
279 file_with_samsam_extension change_default_file_association 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR Splunk_TA_bit9-carbonblack
280 silentcleanup_uac_bypass rundll32_lockworkstation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
281 ntdsutil_export_ntds ping_sleep_batch_command 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
282 disabling_systemrestore_in_registry disabling_remote_user_account_control 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
283 vbscript_execution_using_wscript_app linux_sudoers_tmp_file_creation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
284 office_spawning_control overwriting_accessibility_binaries 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_ossec, Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR
285 detect_regasm_spawning_a_process rundll_loading_dll_by_ordinal 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
286 start_up_during_safe_mode_boot linux_possible_access_or_modification_of_sshd_config_file 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
287 office_product_spawning_mshta system_processes_run_from_unexpected_locations 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
288 change_to_safe_mode_with_network_config spoolsv_spawning_rundll32 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
289 potentially_malicious_code_on_commandline windows_security_account_manager_stopped 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR
290 detect_rundll32_application_control_bypass___advpack windows_process_with_namedpipe_commandline 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
291 services_escalate_exe wbadmin_delete_system_backups 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
292 wget_download_and_bash_execution xsl_script_execution_with_wmic 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
293 remote_wmi_command_attempt linux_add_files_in_known_crontab_directories 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
294 create_or_delete_windows_shares_using_net_exe extraction_of_registry_hives 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
295 unload_sysmon_filter_driver suspicious_rundll32_with_no_command_line_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
296 resize_shadowstorage_volume windows_mof_event_triggered_execution_via_wmi 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
297 wmic_xsl_execution_via_url registry_keys_used_for_persistence 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
298 suspicious_reg_exe_process windows_modify_registry_disable_win_defender_raw_write_notif 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_bit9-carbonblack
299 etw_registry_disabled scheduled_task_creation_on_remote_endpoint_using_at 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
300 process_execution_via_wmi excessive_attempt_to_disable_services 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
301 samsam_test_file_write windows_indirect_command_execution_via_pcalua 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
302 impacket_lateral_movement_commandline_parameters windows_dotnet_binary_in_non_standard_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
303 dump_lsass_via_comsvcs_dll suspicious_searchprotocolhost_no_command_line_arguments 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
304 creation_of_shadow_copy_with_wmic_and_powershell windows_msiexec_unregister_dllregisterserver 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
305 overwriting_accessibility_binaries attempt_to_stop_security_service 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_ossec, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon
306 add_defaultuser_and_password_in_registry windows_installutil_in_non_standard_path 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
307 bits_job_persistence java_class_file_download_by_java_user_agent 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx
308 suspicious_rundll32_dllregisterserver linux_deletion_of_init_daemon_script 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
309 any_powershell_downloadfile getwmiobject_ds_computer_with_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
310 mmc_exe_lolbas_execution_process_spawn linux_stop_services 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
311 w3wp_spawning_shell net_profiler_uac_bypass 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
312 detect_sharphound_command_line_arguments windows_msiexec_spawn_discovery_command 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
313 detect_rclone_command_line_usage linux_ssh_authorized_keys_modification 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
314 suspicious_msbuild_path windows_disable_change_password_through_registry 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
315 disabling_net_user_account windows_remote_services_rdp_enable 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack
316 shim_database_installation_with_suspicious_parameters linux_at_allow_config_file_creation 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
317 dns_query_length_with_high_standard_deviation excel_spawning_powershell 5.0.0 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_isc-bind, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox Splunk_TA_microsoft_sysmon
318 logon_script_event_trigger_execution 5.0.1 Splunk_TA_bit9-carbonblack
319 windows_processes_killed_by_industroyer2_malware 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
320 impacket_lateral_movement_commandline_parameters 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
321 detect_regasm_with_no_command_line_arguments 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
322 office_application_spawn_rundll32_process 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
323 windows_installutil_url_in_command_line 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
324 allow_operation_with_consent_admin 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
325 linux_preload_hijack_library_calls 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
326 windows_installutil_credential_theft 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
327 windows_service_create_kernel_mode_driver 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
328 disabling_net_user_account 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
329 detect_exchange_web_shell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
330 windows_system_logoff_commandline 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
331 windows_msiexec_remote_download 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
332 detect_use_of_cmd_exe_to_launch_script_interpreters 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
333 regsvr32_with_known_silent_switch_cmdline 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
334 linux_pkexec_privilege_escalation 5.0.1 Splunk_TA_microsoft_sysmon
335 reg_exe_manipulating_windows_services_registry_keys 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
336 linux_insert_kernel_module_using_insmod_utility 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
337 add_or_set_windows_defender_exclusion 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
338 suspicious_linux_discovery_commands 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
339 office_product_spawning_wmic 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
340 disable_logs_using_wevtutil 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
341 deleting_of_net_users 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
342 sdelete_application_execution 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
343 remote_process_instantiation_via_wmi_and_powershell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
344 rundll32_shimcache_flush 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
345 suspicious_writes_to_windows_recycle_bin 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
346 modify_acl_permission_to_files_or_folder 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
347 windows_remote_services_allow_rdp_in_firewall 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
348 any_powershell_downloadfile 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
349 schtasks_run_task_on_demand 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
350 remote_system_discovery_with_wmic 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
351 suspicious_reg_exe_process 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
352 windows_msiexec_dllregisterserver 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
353 linux_possible_access_to_sudoers_file 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
354 windows_modify_registry_disabling_wer_settings 5.0.1 Splunk_TA_bit9-carbonblack
355 remote_process_instantiation_via_dcom_and_powershell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
356 screensaver_event_trigger_execution 5.0.1 Splunk_TA_bit9-carbonblack
357 get_domainpolicy_with_powershell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
358 msmpeng_application_dll_side_loading 5.0.1 Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR
359 services_exe_lolbas_execution_process_spawn 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
360 auto_admin_logon_registry_entry 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
361 ryuk_test_files_detected 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR
362 check_elevated_cmd_using_whoami 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
363 creation_of_shadow_copy_with_wmic_and_powershell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
364 linux_shred_overwrite_command 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
365 windows_file_without_extension_in_critical_folder 5.0.1 Splunk_TA_bit9-carbonblack
366 linux_dd_file_overwrite 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
367 disable_windows_app_hotkeys 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
368 getwmiobject_ds_group_with_powershell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
369 office_spawning_control 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
370 execute_javascript_with_jscript_com_clsid 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
371 mshta_spawning_rundll32_or_regsvr32_process 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
372 allow_network_discovery_in_firewall 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
373 suspicious_dllhost_no_command_line_arguments 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
374 linux_high_frequency_of_file_deletion_in_etc_folder 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
375 winword_spawning_powershell 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
376 windows_modify_registry_disallow_windows_app 5.0.1 Splunk_TA_bit9-carbonblack
377 detect_sharphound_command_line_arguments 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
378 wmiprsve_exe_lolbas_execution_process_spawn 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
379 suspicious_wevtutil_usage 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
380 windows_execute_arbitrary_commands_with_msdt 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
381 linux_service_started_or_enabled 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
382 office_document_spawned_child_process_to_download 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
383 windows_odbcconf_load_dll 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
384 attempt_to_add_certificate_to_untrusted_store 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows
385 linux_setuid_using_setcap_utility 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
386 windows_modify_registry_suppress_win_defender_notif 5.0.1 Splunk_TA_bit9-carbonblack
387 linux_setuid_using_chmod_utility 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR
388 office_product_spawning_certutil 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
389 linux_file_creation_in_profile_directory 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
390 windows_service_creation_on_remote_endpoint 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
391 linux_account_manipulation_of_ssh_config_and_keys 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
392 office_product_spawning_bitsadmin 5.0.1 Splunk_TA_microsoft_sysmon Splunk_TA_microsoft_sysmon
393 linux_service_file_created_in_systemd_directory 5.0.1 Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack
File diff suppressed because it is too large Load Diff